--- Cliffe <cliffe@ii.net> wrote:Now that's a refreshing comment. Thank you. There are people (I'm not one of them) who figure that you can solve all the security problems by applying sufficiently fine granularity of on/off permissions. While you're at it, how about a capability for each possible directory entry name? Of course they don't. The only problem they are intended to solve, and I really mean this, is the association of uid 0 with privilege. That's it. You would be better off with a single CAP_GODLIKE than with uid 0 having all privilege all the time. Fine grained capabilities are a bonus, and there are lots of people who think that it would be really nifty if there were a separate capability for each "if" in the kernel. I personally don't see need for more than about 20. That is a matter of taste. DG/UX ended up with 330 and I say that's too many. Casey Schaufler casey@schaufler-ca.com -
| Linus Torvalds | Linux 2.6.27-rc5 |
| Greg Kroah-Hartman | [PATCH 007/196] Chinese: add translation of stable_kernel_rules.txt |
| Kamalesh Babulal | [Build Failure] 2.6.25-rc5-mm1 Build fails with allmodconfig probe_4drives undefined |
| Gabriel C | Re: Linus 2.6.23-rc1 |
| David Woodhouse | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| David Miller | [GIT]: Networking |
| Gerrit Renker | [PATCH 0/37] dccp: Feature negotiation - last call for comments |
git: | |
