Re: Frustrated with capabilities..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Friday, August 29, 2008 - 9:58 am

Quoting Pavel Machek (pavel@suse.cz):

KEEP_CAPS prevents capability set clearing at setuid, not at exec.


They will help.  The context is pI.  When a file is executed, the task's
new permitted set is calculated as:

	pP' = (fI&pI) | (fP & X)

So you can give /bin/foo the file capabilities:
	fI=cap1,cap2,cap3
Then task 1 runs with pI=cap1, so when it executes /bin/foo it will get
	pP' = cap1
Task 2 runs with pI=cap2,cap3,cap4 so when it executes /bin/foo it will
get
	pP' = cap2,cap3

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Frustrated with capabilities.., Markku Savela, (Wed Aug 27, 2:31 am)
Re: Frustrated with capabilities.., Pavel Machek, (Thu Aug 28, 7:18 am)
Re: Frustrated with capabilities.., Markku Savela, (Thu Aug 28, 7:45 am)
Re: Frustrated with capabilities.., Theodore Tso, (Thu Aug 28, 10:48 am)
Re: Frustrated with capabilities.., David P. Quigley, (Thu Aug 28, 2:03 pm)
Re: Frustrated with capabilities.., Casey Schaufler, (Thu Aug 28, 9:47 pm)
Re: Frustrated with capabilities.., Markku Savela, (Fri Aug 29, 3:18 am)
Re: Frustrated with capabilities.., James Morris, (Fri Aug 29, 3:47 am)
Re: Frustrated with capabilities.., Theodore Tso, (Fri Aug 29, 7:07 am)
Re: Frustrated with capabilities.., David P. Quigley, (Fri Aug 29, 7:20 am)
Re: Frustrated with capabilities.., Serge E. Hallyn, (Fri Aug 29, 9:58 am)
Re: Frustrated with capabilities.., Serge E. Hallyn, (Fri Aug 29, 10:11 am)