Re: [PATCH] ptrace: allow restriction of ptrace scope

From: Alan Cox
Date: Thu Jun 17 2010 - 18:31:29 EST


> I don't mind putting them in commoncap at all. I would just like people
> to agree on what they disagree about. :)

I don't believe they belong in commoncap, but as something which can sit
on top of commoncap and then be dropped into by the security modules that
makes total sense.

(Really thats just the stacking debate and how to dodge it ;))

Ie you'd have

optionally:
LSMs
optionally:
cap_switches
required:
commoncap
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/