Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S261154AbVAHNHh (ORCPT ); Sat, 8 Jan 2005 08:07:37 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S261155AbVAHNHh (ORCPT ); Sat, 8 Jan 2005 08:07:37 -0500 Received: from hibernia.jakma.org ([212.17.55.49]:655 "EHLO hibernia.jakma.org") by vger.kernel.org with ESMTP id S261154AbVAHNHV (ORCPT ); Sat, 8 Jan 2005 08:07:21 -0500 Date: Sat, 8 Jan 2005 13:04:25 +0000 (UTC) From: Paul Jakma X-X-Sender: paul@sheen.jakma.org To: Paul Davis cc: Martin Mares , Arjan van de Ven , Christoph Hellwig , Lee Revell , Ingo Molnar , Chris Wright , Alan Cox , "Jack O'Quin" , Linux Kernel Mailing List , Andrew Morton Subject: Re: [PATCH] [request for inclusion] Realtime LSM In-Reply-To: <200501071622.j07GMUCr018735@localhost.localdomain> Message-ID: References: <200501071622.j07GMUCr018735@localhost.localdomain> Mail-Followup-To: paul@hibernia.jakma.org X-NSA: arafat al aqsar jihad musharef jet-A1 avgas ammonium qran inshallah allah al-akbar martyr iraq saddam hammas hisballah rabin ayatollah korea vietnam revolt mustard gas british airways washington MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 818 Lines: 25 On Fri, 7 Jan 2005, Paul Davis wrote: > capabilities work - we use them in 2.4 where a helper suid application > gets the ball rolling, and then its child grants capabilities to new > clients. We use them too in Quagga. Reasonably happy with them. Not a panacae, but far better to retain just a few capabilities, than retaining ruid 0 (as we must on other systems). Only issue really is "graininess" of capabilities, which i'd guess is a double-edged sword. regards, -- Paul Jakma paul@clubi.ie paul@jakma.org Key ID: 64A2FF6A Fortune: Kill Ugly Radio - Frank Zappa - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/