Theodore Y. Ts'o <tytso@MIT.EDU> wrote: > The tradeoff is that "lack of programming" allows people to start > using capabilities in systems without needing to modify the > programs to explicitly make system calls calls to raise their > capability level. You can simply set a program like inetd to have the > CAP_BSD_RESERVED_PORT_REALLY_BAD_IDEA capability, and you're done.
Except that inetd itself isn't such a hot idea.
--
Raul, a tcpserver fan
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu