Re: caps in elf headers: use the sticky bit!

Krzysztof Halasa (khc@intrepid.pm.waw.pl)
11 Apr 1999 12:22:14 +0200


"David L. Parsley (lkml account)" <kparse@salem.k12.va.us> writes:

> If the file owner can directly edit a file which has it's capabilities
> stored in the elf headers, then they can set any flags they desire without
> using any special capability utility. So the file must be immutable when
> caps are enabled.

But when caps are set in the fs, you don't need to worry about such things.
Anyway, you are unable to store all file info in, say, tar archives
or via nfs - think of file attrs or ACLs.
I think until tools are enhanced to support such things, they shouldn't
see/transport any increased file rights.

-- 
Krzysztof Halasa
Network Administrator of The Palace of Youth in Warsaw

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/