* Crispin Cowan (crispin@crispincowan.com) wrote:OK, that's what I thought you were saying. I don't actually see your distinction here between those two environments; why does it matter if there is one non-priveliged user or many? I think it might depend on how strict the users starting point is; you could say: 1 This document editor can read and write any part of the users home directory other than the . files. or you could say: 2 This document editor can read any files but only write to the 'Documents directory'. If the adminisrator set something up with (2) as the starting point it would seem reasonable for the user to be able to add the ability to edit documents in extra directories for their style of organising documents they work on; but they would be restricted in what they could add so that they couldn't add the ability to write to their settings files. Well that would correspond to case (1) above; where the global settings by an administrator were fairly open and then it was up to the user to restrict programs more if they knew they always stored their documents in one place; I was working on the basis of allowing applications access to very little until you said it was alright - since most users wouldn't actually bother up setting up more restrictive access. <snip> That solution might answer my questions anyway. <snip> Allowing a user to tweak (under constraints) their settings might allow them to do something like create two mozilla profiles which are isolated from each other, so that the profile they use for general web surfing is isolated from the one they use for online banking. Dave -- -----Open up your eyes, open up your mind, open up your code ------- / Dr. David Alan Gilbert | Running GNU/Linux on Alpha,68K| Happy \ \ gro.gilbert @ treblig.org | MIPS,x86,ARM,SPARC,PPC & HPPA | In Hex / \ _________________________|_____ http://www.treblig.org |_______/ -
| Glauber de Oliveira Costa | [PATCH 0/19] desc_struct integration |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| jmerkey | [ANNOUNCE] mdb: Merkey's Linux Kernel Debugger 2.6.27-rc4 released |
| Oliver Pinter | Re: x86: 4kstacks default |
git: | |
| Linus Torvalds | Re: VCS comparison table |
| Mark Junker | git on MacOSX and files with decomposed utf-8 file names |
| Junio C Hamano | Re: More precise tag following |
| Len Brown | fatal: unable to create '.git/index': File exists |
| Mayuresh Kathe | Re: What is our ultimate goal?? |
| Diana Eichert | Re: OpenBSD on decTOP? |
| Richard Stallman | Real men don't attack straw men |
| knitti | Re: HP Procurve or Soekris w. OpenBSD ? |
| Mark Lord | Re: 2.6.25-rc8: FTP transfer errors |
| Andi Kleen | [PATCH RFC] [1/9] Core module symbol namespaces code and intro. |
| Ritesh Kumar | SO_RCVBUF doesn't change receiver advertised window |
| Evgeniy Polyakov | Re: [BUG] New Kernel Bugs |
