[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Preparing Debian for using capabilities: file ownership.



Previously Nicolás Lichtmaier wrote:
>  Yes, you are right, I was probably too optimisitic with that. But, perhaps,
> the "general change" will be the modification of EXT2 to support "resource
> forks", but the needed changes in the VFS are probably small, and perhaps,
> one of those new filesystems will include capabilities before ext2 does...

I wonder if you're read linux-kernel recently, resource forks definitely
will never be part of (mainstream) Linux. Nasty evil things!

The changes to the VFS will probably be minimal, but they do require
people agree on a flexible way to handle all kinds of attributes without
tieing things down to a single (or even the set of currently existing) 
filesystem(s).

> But anyway, capabilities are useable without fs support.

Definitely. Some daemons like proftpd already use them.

Also, keep in mind that the set of capilities differs between 2.2 and
2.4 kernels if memory serves me correctly, and people are still looking
at making sure the current set is an optimal one. (Fun assignment: see
which capabilities can lead to root access. It turns out to be a
surprisingly large set).

Wichert.

-- 
   ________________________________________________________________
 / Generally uninteresting signature - ignore at your convenience  \
| wichert@liacs.nl                    http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |



Reply to: