Lower Process Capabilities

Joe Nall joe at nall.com
Wed Jul 29 14:07:39 UTC 2009


On Jul 29, 2009, at 8:49 AM, Serge E. Hallyn wrote:
>
> The same thing can happen at the moment with capabilities for an NFS
> rootfs,

prelink killed file caps on fedora last time I checked. Makes them  
useless for general purpose app protection.
https://bugzilla.redhat.com/show_bug.cgi?id=456105

joe


> so perhaps the same solution (falling back to classic setuid
> if there is no selinux policy loaded) could apply?
>
> -serge
>
> -- 
> fedora-devel-list mailing list
> fedora-devel-list at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-devel-list




More information about the devel mailing list