It's not dead, it's just not being integrated mostly because of lack
of feedback. Linux-privs works. When 2.2 is out, I'll make a patch for
those interested in using it (I am :-) and hopefully it will get into
2.3 ASAP.
Linux-privs has both capabilities and a system-wide
"securebits". Securebits works as a filter which the per-process
filesystem-given ("suid") capabilities is filtered through. You can't
gain more capabilities than the system-wide "securebits" allow you. So
you can restrict the system just like BSD securelevel. However, the
mapping between "level" and bitmask will be a user-level policy.
astor
-- Alexander Kjeldaas, Guardian Networks AS, Trondheim, Norway http://www.guardian.no/- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu