Re: patch to make Linux capabilities into something useful (v 0.3.1)

From: Bernd Eckenfels
Date: Fri Sep 08 2006 - 15:07:11 EST


On Fri, Sep 08, 2006 at 04:39:47PM +0200, Pavel Machek wrote:
> Well, then mistake was running that daemon with elevated priviledges
> in the first place.

there are workers out there which expect to be started priveldged, do
something (bind, suid, ...) and then drop priveledges. If those check if the
drop is needed based on the euid...

Of course this can be solved better, however i remeber that those cases are
the ones where compatibility means any priveledge -> euid = 0.

Anyway, I think there is something like that in the proposed patch, so it
looks good.

Gruss
Bernd
--
(OO) -- Bernd_Eckenfels@Mörscher_Strasse_8.76185Karlsruhe.de --
( .. ) ecki@{inka.de,linux.de,debian.org} http://www.eckes.org/
o--o 1024D/E383CD7E eckes@IRCNet v:+497211603874 f:+49721151516129
(O____O) When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl!
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/