On Tue, Aug 31, 2004 at 01:21:47PM +0300, Nadav Har'El wrote: > You can try doing this with Linux's little-known "capabilities" feature. > This allows you to have any user id, but with some of root's capabilities, > like binding any network address or writing any file (for example) > magically turned on. For your protection, you can even enable some capabilties > but not others.
I'm well aware of capabilities, and it was working "as advertised", it would've done the work. Unfortunately, it doesn't. The kernel support is supposedly there, but the userspace tools are broken and have been broken for a long time. See http://www.uwsg.iu.edu/hypermail/linux/kernel/0404.0/0338.html for example. Also AFAICR capabilities are not retained accross exec, which is something I need. Thanks, Muli -- Muli Ben-Yehuda http://www.mulix.org | http://mulix.livejournal.com/
signature.asc
Description: Digital signature
