On Wed, Jan 07, 2009 at 06:52:27PM +0200, Rémi Denis-Courmont (rdenis@simphalempin.com) wrote:
If setting that rlimit does not require admin priviledges, then it does
not require to drop this. So it is superuser or admin who does this.
And exactly the same can be achieved with 'owner' iptables module.
If process itself changes own rlimit, then it is not a rlimit, but a
hint to how it is supposed to work.
Plus I did not see how fork is protected, i.e. does children get the
same rlimit, it looks like it does not.
Security and unpriveledged setup are mutually impossible cases.
--
Evgeniy Polyakov
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html