Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Chris Friedhoff
Date: Tuesday, November 20, 2007 - 2:46 am

On Mon, 19 Nov 2007 17:16:44 -0600
"Serge E. Hallyn" <sergeh@us.ibm.com> wrote:


Yes, I'm booting in a runlevel without a session manager and starting
my X session with xinit.
(slackware: console->runlevel 3; sessionmanager->runlevel 4 )


No, since I'm using capabilities and I'm very happy with it, I grant
cap_kill to xinit. For myself the problem is solved ...



... but if some user decides to configure capabilities into the 2.6.24
kernel or just uses such a kernel and
1) is not granting cap_kill to xinit, and
2) starts X by issuing xinit on the console
3) ends after some time his X session, to come back to the console

he will see a different behavior compared to 2.6.23 exiting his X
session and (I think) believes to have a bug in the X package.

Andrew Morton describes the problem here, too:
http://lkml.org/lkml/2006/11/23/15
http://lkml.org/lkml/2006/11/23/19

Am I wrong in the assumption, but should one not accept an unchanged
behavior with or without capabilities in the kernel regarding the
behavior of applications, when he is not actually using (by not setting
the xattr capability) capabilities with this application?

If I'm wrong, maybe a warning or hint should be given that one has to
grant cap_kill to xinit to come back to the console if the X session
was started by xinit.


Chris



--------------------
Chris Friedhoff
chris@friedhoff.org
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Posix file capabilities in 2.6.24rc2, Chris Friedhoff, (Tue Nov 13, 3:07 pm)
Re: Posix file capabilities in 2.6.24rc2, Serge E. Hallyn, (Tue Nov 13, 4:53 pm)
Re: Posix file capabilities in 2.6.24rc2, Chris Friedhoff, (Wed Nov 14, 2:12 am)
Re: Posix file capabilities in 2.6.24rc2, Serge E. Hallyn, (Wed Nov 14, 11:02 am)
Re: Posix file capabilities in 2.6.24rc2, Chris Friedhoff, (Thu Nov 15, 3:02 pm)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Chris Friedhoff, (Mon Nov 19, 6:39 am)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Serge E. Hallyn, (Mon Nov 19, 4:16 pm)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Chris Friedhoff, (Tue Nov 20, 2:46 am)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Serge E. Hallyn, (Tue Nov 20, 7:51 am)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Chris Friedhoff, (Tue Nov 20, 3:29 pm)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Serge E. Hallyn, (Tue Nov 20, 3:51 pm)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Chris Friedhoff, (Tue Nov 20, 5:50 pm)
Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3, Andrew Morgan, (Thu Nov 22, 12:42 am)