On Tue, Aug 31, 2004 at 01:21:47PM +0300, Nadav Har'El wrote:

> You can try doing this with Linux's little-known "capabilities" feature.
> This allows you to have any user id, but with some of root's capabilities,
> like binding any network address or writing any file (for example)
> magically turned on. For your protection, you can even enable some capabilties
> but not others.

I'm well aware of capabilities, and it was working "as advertised", it
would've done the work. Unfortunately, it doesn't. The kernel support
is supposedly there, but the userspace tools are broken and have been
broken for a long time. See
http://www.uwsg.iu.edu/hypermail/linux/kernel/0404.0/0338.html for
example. Also AFAICR capabilities are not retained accross exec, which
is something I need. 

Thanks, 
Muli
-- 
Muli Ben-Yehuda
http://www.mulix.org | http://mulix.livejournal.com/

Attachment: signature.asc
Description: Digital signature

Reply via email to