Anders Blomdell wrote:
> CAP_DAC_OVERRIDE fixes this issue (and how safe is that :-( )
> 
> How necessary are CAP_SYS_RAWIO and CAP_DAC_OVERRIDE [the two capabiltities i
> think have the most severe security implications] when main has started 
> running,
> i.e. could I drop them after initialization and still do something useful?

Again: you have just found some reason why Xenomai is unsecure, it just
proves that it is unsecure and there are probably other reasons why it
is unsecure. So, here I do not concur with Jan. Security *is* a
black-and-white domain. Any security hole makes the system unsecure,
there is no gray area, no "partially secure" code.

Either you are ready to make a thourough auditing of the code and plug
all the security holes you find, or you consider Xenomai unsecure.
Plugging two holes you have found and say "I stop now, this is
'reasonably' secure" does not really make sense.

-- 
                                            Gilles.

_______________________________________________
Xenomai-help mailing list
[email protected]
https://mail.gna.org/listinfo/xenomai-help

Reply via email to