Re: CAP_SYS_ADMIN on restart(2)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Thursday, April 16, 2009 - 9:29 am

Quoting Alexey Dobriyan (adobriyan@gmail.com):

Now I suppose what we could do is define a new CAP_SYS_RESTART
capability and require that.  Then the admin to whom I'm trying
to cater could simply 'capset cap_sys_restart=pe /bin/restart'.
Then all users could use restart without being granted the
extra privilege implied by CAP_SYS_ADMIN.

-serge
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Thu Apr 9, 7:32 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Thu Apr 9, 7:44 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Dave Hansen, (Thu Apr 9, 10:07 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Ingo Molnar, (Fri Apr 10, 1:28 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Fri Apr 10, 4:45 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Linus Torvalds, (Fri Apr 10, 8:06 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Mon Apr 13, 12:39 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Mon Apr 13, 2:14 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Dave Hansen, (Mon Apr 13, 4:16 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Dave Hansen, (Mon Apr 13, 11:07 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Linus Torvalds, (Mon Apr 13, 11:39 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Ingo Molnar, (Mon Apr 13, 12:30 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Oren Laadan, (Mon Apr 13, 9:26 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Oren Laadan, (Mon Apr 13, 10:46 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 5:29 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Ingo Molnar, (Tue Apr 14, 6:44 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 7:58 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 8:19 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 9:53 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Linus Torvalds, (Tue Apr 14, 10:09 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Randy Dunlap, (Tue Apr 14, 10:19 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Linus Torvalds, (Tue Apr 14, 10:32 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Oren Laadan, (Tue Apr 14, 11:08 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 11:34 am)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Oren Laadan, (Tue Apr 14, 12:31 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 1:08 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Alexey Dobriyan, (Tue Apr 14, 1:49 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Dave Hansen, (Tue Apr 14, 2:11 pm)
Re: [PATCH 00/30] C/R OpenVZ/Virtuozzo style, Serge E. Hallyn, (Tue Apr 14, 2:39 pm)
Re: CAP_SYS_ADMIN on restart(2), Oren Laadan, (Wed Apr 15, 2:05 pm)
Re: CAP_SYS_ADMIN on restart(2), Serge E. Hallyn, (Wed Apr 15, 2:16 pm)
Re: CAP_SYS_ADMIN on restart(2), Alexey Dobriyan, (Thu Apr 16, 8:35 am)
Re: CAP_SYS_ADMIN on restart(2), Serge E. Hallyn, (Thu Apr 16, 9:29 am)