Re: [patch 2.1.97] more capabilities support

Raul Miller (rdm@test.legislate.com)
Wed, 22 Apr 1998 22:16:28 -0400


Theodore Y. Ts'o <tytso@MIT.EDU> wrote:
> The tradeoff is that "lack of programming" allows people to start
> using capabilities in systems without needing to modify the
> programs to explicitly make system calls calls to raise their
> capability level. You can simply set a program like inetd to have the
> CAP_BSD_RESERVED_PORT_REALLY_BAD_IDEA capability, and you're done.

Except that inetd itself isn't such a hot idea.

-- 
Raul, a tcpserver fan

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu