Re: caps in elf headers: use the sticky bit!

David L. Parsley (kparse@salem.k12.va.us)
Mon, 12 Apr 1999 16:49:47 -0400 (EDT)


Hello! (again!)

On Sun, 11 Apr 1999, Pavel Machek wrote:

> You do not want this kind of support in kernel. Believe me. Better use
> setuid0 as marker (those are already immutable) and userspace suid
> program which implements your CAP_SETFCAP.

This applies just as well to the sticky bit solution; if it's not feasible
to have the kernel check the caps in the file when setting the cap flag,
you could still have a userspace util that did all the real work. Good
idea!

>
> Pavel
> --
> I'm really pavel@atrey.karlin.mff.cuni.cz. Pavel
> Look at http://atrey.karlin.mff.cuni.cz/~pavel/ ;-).
>

- --
David L. Parsley
Network Specialist
City of Salem Schools

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/