Re: [PATCH v1 2/2] run-init: Add drop_capabilities support.

From: H. Peter Anvin
Date: Tue Aug 02 2011 - 20:49:23 EST


On 08/02/2011 04:37 PM, Mike Waychison wrote:
>
> Perhaps the right approach is to not drop the effective and permitted
> masks as Andrew pointed out, and do all this from kinit, not from
> run-init while /proc is mounted?
>

Well, we should really move /proc et al into the new root, if nothing
else to match switch_root.

-hpa

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/