Re: disable-cap-mlock

From: Chris Wright
Date: Thu Apr 01 2004 - 21:35:00 EST


* Andrew Morton (akpm@xxxxxxxx) wrote:
> Andrea Arcangeli <andrea@xxxxxxx> wrote:
> > just curious, how does this work through 'su'? Does su check
> > logincap.conf too?
>
> I guess so.

Or let pam_cap do it so you don't have to modify all the apps just the pam
confs.

> Well you have a local short-term solution...
>
> One thing I was wondering was whether /proc/sys/vm/disable_cap_mlock should
> hold a GID rather than a boolean. So you do
>
> echo groupof oracle > /proc/sys/vm/disable_cap_mlock

Heh, was just thinking the same.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/