On Tue, Aug 09, 2005 at 01:52:06PM -0700, Chris Wright wrote: > * Bodo Eggert ([EMAIL PROTECTED]) wrote: > > How are you going to tell processes that may exec suid (or set-capability-) > > programs from those that aren't supposed to gain certain capabilities? > > typically you'd expect exec suid will reset to full caps.
suid exec _must_ reset to full caps or we have the sendmail disaster again. However, that is _if_ execve() succeeds. It is quite possible that execve() should fail, and that is precisely what my patch does: if a process has bounded capabilities, it _may not_ exec suid. -- David A. Madore ([EMAIL PROTECTED], http://www.madore.org/~david/ ) - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/