Re: Fw: [PATCH 1/1] file capabilities: simplify signal check

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: serge
Date: Tuesday, February 26, 2008 - 9:18 pm

Quoting Eric W. Biederman (ebiederm@xmission.com):

... and owned by the same uid, since the case of owned by a different
uid is handled earlier.


Yes, although it might be a good idea to be stricter when
issecure(SECURE_NOROOT), which will become meaningful when Andrew
Morgan's per-process securebits patch gets more use.


Yes, the only difference right now is that some of the euid/uid/suid
combos aren't allowed for in cap_task_kill().  If we're not going to
be stricter with SECURE_NOROOT, then I plan to try to remove
cap_task_kill() and just apologize for the huge mess it caused.

-serge

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Fw: [PATCH 1/1] file capabilities: simplify signal check, Eric W. Biederman, (Sat Feb 23, 11:50 pm)
Re: Fw: [PATCH 1/1] file capabilities: simplify signal check, serge, (Tue Feb 26, 9:18 pm)
Re: Fw: [PATCH 1/1] file capabilities: simplify signal check, Eric W. Biederman, (Thu Feb 28, 1:25 pm)