Is there any way in Linux/AppArmor to prevent a process from modifying
its process group ID,(i.e. by calling setpgid)? I need to do so
because I am creating a sandbox, and I want to be able to kill a
process and all of its children after n seconds. I am identifying the
children from the process group id, so I need to make sure this value
cannot be changed.

There is someting called CAP_SETGID but I think this refers to the
process' user-group id, i.e. what is set by setgid which is something
different from setpgid.

-- 
AppArmor mailing list
[email protected]
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/apparmor

Reply via email to