Joerg Schilling wrote:
> If we start talking about isaexec, we should also talk about pfexec. I would 
> like to see the code moved into the kernel. Other possible ways of getting 
> rid 
> of a userspace implementation for the pfexec features would be to implement 
> something like capabilities that may replace 
> suid(0) to setppriv(cap-list from filesystem).

See http://www.opensolaris.org/os/project/fgap/

        Scott

Reply via email to