Re: Is CAP_SYS_ADMIN checked by every program !?

From: Bernd Eckenfels (ecki-news2004-12_at_lina.inka.de)
Date: 12/30/04

  • Next message: Folkert van Heusden: "[2.6.9] kernel BUG at mm/rmap.c:474! (more details)"
    To: linux-kernel@vger.kernel.org
    Date:	Thu, 30 Dec 2004 07:13:38 +0100
    
    

    In article <200412300546.iBU5kVie023979@turing-police.cc.vt.edu> you wrote:
    > If you actually log your kernel messages it can matter, if every single
    > process suddenly starts dumping a line in your syslogs, especially on a
    > busy system...

    It does not, the patch is not part of the linux kernel. There is nothing
    which is tracing permission checks.

    Of course this might become interesting, if you want to do full audit log,
    however the current functionality in the kernel infrastructure is not very
    well suited for that, since you would habe to do stack analysis for
    meaningful traces (like "who checked access permission, why")

    Gruss
    Bernd
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at http://www.tux.org/lkml/


  • Next message: Folkert van Heusden: "[2.6.9] kernel BUG at mm/rmap.c:474! (more details)"

    Relevant Pages

    • Re: 2.6.9: serial_core: uart_open
      ... and ensure that you have a large kernel ... log buffer. ... You can then read the kernel messages with dmesg - you may need the ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Soekris not execing INIT
      ... > I'm not sure that this is a specific kernel issue or not, ... > set to ttyS0,19200n81, and the kernel messages show up fine and everything ... init doesn't get executed. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Mouse issues in -mm
      ... > stopped working at some point later (with no obvious kernel messages). ... > kernel without the touchpad problems. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: 2.6.7-rc2-mm2
      ... But my kernel does not boot, it stops at ... Does not look like kernel messages to me. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: printk functionality
      ... sufficient as I dont want the other kernel messages. ... By kernel defined files, I meant that KERN_INFO ... >> I want to add functionality to the printk function such that I can read ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)