Re: [RFC][PATCH] Add LSM sysctl hook to 2.5.59

From: Christoph Hellwig (
Date: Sun Jan 19 2003 - 19:43:20 EST

On Mon, Jan 20, 2003 at 01:39:39AM +0100, Russell Coker wrote:
> > What's the reason you can't just live with DAC for sysctls?
> What exactly do you mean by "live with DAC" in this context? If you mean
> "allow UID==0 processes to do whatever they like" then it's not going to work
> for any sort of chroot setup.

This means check the unix file permissions / ACLs only overriden by
CAP_FOWNER processes.

To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to
More majordomo info at
Please read the FAQ at

This archive was generated by hypermail 2b29 : Thu Jan 23 2003 - 22:00:22 EST