Jan Kara <[EMAIL PROTECTED]> writes: > On Thu 01-11-07 20:49:32, Olaf Dietsche wrote: >> Jan Kara <[EMAIL PROTECTED]> writes: >> >> >> This patch implements filesystem capabilities. It allows to >> >> run privileged executables without the need for suid root. >> > Hmm, is there some "design document" so that one does not have to poke >> > through the code and find out what it's actually trying to do? >> >> What do you mean with "trying to do"? I thought this is obvious, it >> provides executables with filesystem capabilities. > Well, yes, that was obvious but I rather meant "how is it doing it?". > So where does it store these bits and such.
The bits are stored in a sparse file named /.capabilities in the directory of the mount point, where the corresponding executable lives. The inode number of the file is the index into this file. Regards, Olaf. - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

