public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Status of capabilities?
@ 2002-06-26 12:40 Michael Kerrisk
  2002-06-27  6:05 ` Dax Kelson
  0 siblings, 1 reply; 8+ messages in thread
From: Michael Kerrisk @ 2002-06-26 12:40 UTC (permalink / raw)
  To: linux-kernel

When I asked the question below a while back, I got no response.  Is there
really noone who can say anything about the future of capabilities?

Cheers

Michael

------- Forwarded message follows -------
Date sent:       Fri, 10 May 2002 08:28:55 +0200 (MEST)
From:            Michael Kerrisk <m.kerrisk@gmx.net>
Subject:         Status of capabilities?
To:              linux-kernel@vger.kernel.org

Gidday,

What are the current status and future of capabilites?  There seems to be no
up-to-date information on this anywhere.

It seems capabilities have been partly implemented since 2.2.  That is to
say:

1. The kernel checks (effective) capabilities when performing various
operations.

2. System calls are provided to raise and lower capabilties

What's still missing in 2.4, as far as I can see after reading the sources,
is the ability to set capabilities on executable files so that a process
gains those privileges when executing the file.  I recall seeing some
information somewhere saying this wasn't possible / wasn't going to happen
for ext2.  Is it on the drawing board for any file system?

Thanks

Michael



^ permalink raw reply	[flat|nested] 8+ messages in thread
* Re: Status of capabilities?
@ 2002-06-28 13:20 Jesse Pollard
  0 siblings, 0 replies; 8+ messages in thread
From: Jesse Pollard @ 2002-06-28 13:20 UTC (permalink / raw)
  To: chris, Jesse Pollard; +Cc: dax, Michael Kerrisk, linux-kernel

Chris Wright <chris@wirex.com>:
> * Jesse Pollard (pollard@tomcat.admin.navo.hpc.mil) wrote:
> > 
> > Actually, I think most of that work has already been done by the Linux
> > Security Module project (well, except #7).
> 
> The LSM project supports capabilities exactly as it appears in the
> kernel right now.  The EA linkage is still missing.  Of course, we are
> accepting patches ;-)

Absolutely - I was just meaning that the effort of identifing the location(s)
in the kernel the hooks will have to be to set the capabilities from the EA
reference has been done. And in a central location too. Also, the hooks in the
filesystem will provide the location, if not access to, the EA when they
become available in/to the VFS (at least I hope that's where they end up).

-------------------------------------------------------------------------
Jesse I Pollard, II
Email: pollard@navo.hpc.mil

Any opinions expressed are solely my own.

^ permalink raw reply	[flat|nested] 8+ messages in thread
* Status of capabilities?
@ 2002-05-10  6:28 Michael Kerrisk
  0 siblings, 0 replies; 8+ messages in thread
From: Michael Kerrisk @ 2002-05-10  6:28 UTC (permalink / raw)
  To: linux-kernel

Gidday,

What are the current status and future of capabilites?  There seems to be no
up-to-date information on this anywhere.

It seems capabilities have been partly implemented since 2.2.  That is to
say:

1. The kernel checks (effective) capabilities when performing various
operations.

2. System calls are provided to raise and lower capabilties

What's still missing in 2.4, as far as I can see after reading the sources,
is the ability to set capabilities on executable files so that a process
gains those privileges when executing the file.  I recall seeing some information
somewhere saying this wasn't possible / wasn't going to happen for ext2.  Is
it on the drawing board for any file system?  

Thanks

Michael

-- 
GMX - Die Kommunikationsplattform im Internet.
http://www.gmx.net


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2002-07-06 20:55 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-06-26 12:40 Status of capabilities? Michael Kerrisk
2002-06-27  6:05 ` Dax Kelson
2002-06-27 12:57   ` Jesse Pollard
2002-06-27 20:54     ` Chris Wright
2002-06-27 22:52       ` Dax Kelson
2002-07-06 20:56         ` Chris Wright
  -- strict thread matches above, loose matches on Subject: below --
2002-06-28 13:20 Jesse Pollard
2002-05-10  6:28 Michael Kerrisk

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox