Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S966188AbbBCR04 (ORCPT ); Tue, 3 Feb 2015 12:26:56 -0500 Received: from h2.hallyn.com ([78.46.35.8]:43596 "EHLO h2.hallyn.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S965362AbbBCR0y (ORCPT ); Tue, 3 Feb 2015 12:26:54 -0500 Date: Tue, 3 Feb 2015 18:26:53 +0100 From: "Serge E. Hallyn" To: Christoph Lameter Cc: "Serge E. Hallyn" , Serge Hallyn , Serge Hallyn , Andy Lutomirski , Jonathan Corbet , Aaron Jones , "Ted Ts'o" , linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, akpm@linuxfoundation.org, morgan@kernel.org Subject: Re: [capabilities] Allow normal inheritance for a configurable set of capabilities Message-ID: <20150203172653.GB4748@mail.hallyn.com> References: <20150202171257.GD24351@ubuntumail> <20150203155544.GE2923@mail.hallyn.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1141 Lines: 24 Quoting Christoph Lameter (cl@linux.com): > On Tue, 3 Feb 2015, Serge E. Hallyn wrote: > > > We've currently got two proposals. (Three includig yours; but I explained my > > problem with yours earlier this morning - do appreciate the proposal and > > the patch though, really, thanks) It's worth digging into the details of > > each, but if they end up complicating things then perhaps "dropping > > capabilities and going with something new" ought to be another proposal. > > Ok that is about the binding to a person and executable? It's about at least making it per-process(-tree). > So you think there should be a cap_inheritable mask settable in the caps > of each file. No. I mean, we have that now. I just want to require a privileged process to fill in the pA in the first place. If people are currently using file caps "as intended" I don't want behavior to change for them. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/