Re: [RFC][PATCH] scripts with stdin replaced

Ralf Baechle (ralf@uni-koblenz.de)
Thu, 8 Jul 1999 11:23:23 +0200


On Tue, Jul 06, 1999 at 08:44:23AM -0400, Horst von Brand wrote:

> > Probably the only safe well-known interpreter is perl, and that runs
> > setuid scripts itself already.
>
> That is a kludge, and it won't work at all when capabilities are done right
> in the filesystem.

I don't see why Perl's mechanism for SUID scripts used on Linux couldn't
be expanded to cover capabilites as well. Except that that would make
as small part of Perl the single point of failure in the security system.

Ralf

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/