Re: Capabilities help

From: Chris Wright (chrisw_at_osdl.org)
Date: 01/14/04

  • Next message: Matt Mackall: "Re: netpoll bug - kgdboe on x86_64"
    Date:	Tue, 13 Jan 2004 17:05:05 -0800
    To: john moser <bluefoxicy@linux.net>
    
    

    * john moser (bluefoxicy@linux.net) wrote:
    > I know this is working, because I checked my code over, plus the double
    > chroot / fails. I can still load modules, change the system time,
    > and administrate the network.

    First are you sure you dropped those particular bits? Assuming you are,
    what's your .config look like (esp. CONFIG_SECURITY_*)? Can you show me
    that your process is dropping a capability (say from /proc/<pid>/status),
    and that the capability is still enabled?

    thanks,
    -chris

    -- 
    Linux Security Modules     http://lsm.immunix.org     http://lsm.bkbits.net
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at  http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at  http://www.tux.org/lkml/
    

  • Next message: Matt Mackall: "Re: netpoll bug - kgdboe on x86_64"

    Relevant Pages

    • Capabilities help
      ... Okay it seems that in my jail, when a process attatches (with the ... I can still load modules, change the system time, and administrate the ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: A problem about DIRECT IO on ext3
      ... fails if the offset or buffer is NOT filesystem blocksize ... So, its possible that your buffer is atleast 512byte aligned, ... > soft/hard sector sizes. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [RFC] IDE/ATA/SATA controller hotplug
      ... > 1) be first class modules, where all controllers/adapters are ... > certainly do not care about having this capability. ... Not in a arch specific dir please. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: offtopic: how to break huge patch into smaller independent patches?
      ... if all else fails, ... but the option parsing ... espdiff: invalid option -- h ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH][2/2] ide-tape: small cleanups - handle copy_to|from_user() failures
      ... > won't this result in the whole i/o being treated as invalid? ... That was my original thought "if copy_from_user fails then something ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)