Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-21 Thread Andrew Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Serge E. Hallyn wrote: > The problem is that when you run a setuid binary, its pP and pE are > fully raised. The following patch fixes it for me. Chris, does it fix > your problem? Andrew, am I again confusing myself and doing something > unsafe?

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-21 Thread Andrew Morgan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Serge E. Hallyn wrote: The problem is that when you run a setuid binary, its pP and pE are fully raised. The following patch fixes it for me. Chris, does it fix your problem? Andrew, am I again confusing myself and doing something unsafe? I

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Tue, 20 Nov 2007 16:51:21 -0600 "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > On Tue, 20 Nov 2007 08:51:06 -0600 > > "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > > > > > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > > > On Mon, 19 Nov

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): > On Tue, 20 Nov 2007 08:51:06 -0600 > "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > > > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > > On Mon, 19 Nov 2007 17:16:44 -0600 > > > "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > > > > > > > Quoting

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Tue, 20 Nov 2007 08:51:06 -0600 "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > On Mon, 19 Nov 2007 17:16:44 -0600 > > "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > > > > > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > > > Hello Serge, > > >

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): > On Mon, 19 Nov 2007 17:16:44 -0600 > "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > > > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > > Hello Serge, > > > > > > just to let you know: with 2.6.24-rc3 I have the same problem. > > > > Ok, so here

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Mon, 19 Nov 2007 17:16:44 -0600 "Serge E. Hallyn" <[EMAIL PROTECTED]> wrote: > Quoting Chris Friedhoff ([EMAIL PROTECTED]): > > Hello Serge, > > > > just to let you know: with 2.6.24-rc3 I have the same problem. > > Ok, so here is the flow. > > First off, using runlevel 5 on FC7, using 'log

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Mon, 19 Nov 2007 17:16:44 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello Serge, just to let you know: with 2.6.24-rc3 I have the same problem. Ok, so here is the flow. First off, using runlevel 5 on FC7, using 'log out' correctly

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Mon, 19 Nov 2007 17:16:44 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello Serge, just to let you know: with 2.6.24-rc3 I have the same problem. Ok, so here is the flow. First

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Tue, 20 Nov 2007 08:51:06 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Mon, 19 Nov 2007 17:16:44 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello Serge, just to let you

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Tue, 20 Nov 2007 08:51:06 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Mon, 19 Nov 2007 17:16:44 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-20 Thread Chris Friedhoff
On Tue, 20 Nov 2007 16:51:21 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Tue, 20 Nov 2007 08:51:06 -0600 Serge E. Hallyn [EMAIL PROTECTED] wrote: Quoting Chris Friedhoff ([EMAIL PROTECTED]): On Mon, 19 Nov 2007 17:16:44 -0600

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-19 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): > Hello Serge, > > just to let you know: with 2.6.24-rc3 I have the same problem. Ok, so here is the flow. First off, using runlevel 5 on FC7, using 'log out' correctly brings you back to a new login prompt. Your problem is starting in runlevel 3,

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-19 Thread Chris Friedhoff
Hello Serge, just to let you know: with 2.6.24-rc3 I have the same problem. Chris On Thu, 15 Nov 2007 23:02:27 +0100 Chris Friedhoff <[EMAIL PROTECTED]> wrote: > No, the patch doesn't fix the problem. > I still have the black screen with the cursor when I close the > xsession, only the

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-19 Thread Chris Friedhoff
Hello Serge, just to let you know: with 2.6.24-rc3 I have the same problem. Chris On Thu, 15 Nov 2007 23:02:27 +0100 Chris Friedhoff [EMAIL PROTECTED] wrote: No, the patch doesn't fix the problem. I still have the black screen with the cursor when I close the xsession, only the

Re: Posix file capabilities in 2.6.24rc2; now 2.6.24-rc3

2007-11-19 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello Serge, just to let you know: with 2.6.24-rc3 I have the same problem. Ok, so here is the flow. First off, using runlevel 5 on FC7, using 'log out' correctly brings you back to a new login prompt. Your problem is starting in runlevel 3, and

Re: Posix file capabilities in 2.6.24rc2

2007-11-15 Thread Chris Friedhoff
No, the patch doesn't fix the problem. I still have the black screen with the cursor when I close the xsession, only the windowmanager is closed. consolemessage: xinit: Operation not permitted (errno 1): Can't kill X server kernel has capabilities, xinit has no caps granted. Chris > I'm

Re: Posix file capabilities in 2.6.24rc2

2007-11-15 Thread Chris Friedhoff
No, the patch doesn't fix the problem. I still have the black screen with the cursor when I close the xsession, only the windowmanager is closed. consolemessage: xinit: Operation not permitted (errno 1): Can't kill X server kernel has capabilities, xinit has no caps granted. Chris I'm setting

Re: Posix file capabilities in 2.6.24rc2

2007-11-14 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): > Hello Serge, > > I wanted only to express what I observed. > > A "yes it should" confirms its ok. > > And yes, I haven't looked into the patches and the name and commentary > of file-capabilities-clear-fcaps-on-inode-change.patch explains this >

Re: Posix file capabilities in 2.6.24rc2

2007-11-14 Thread Chris Friedhoff
Hello Serge, I wanted only to express what I observed. A "yes it should" confirms its ok. And yes, I haven't looked into the patches and the name and commentary of file-capabilities-clear-fcaps-on-inode-change.patch explains this already. I'm preparing to update my page

Re: Posix file capabilities in 2.6.24rc2

2007-11-14 Thread Chris Friedhoff
Hello Serge, I wanted only to express what I observed. A yes it should confirms its ok. And yes, I haven't looked into the patches and the name and commentary of file-capabilities-clear-fcaps-on-inode-change.patch explains this already. I'm preparing to update my page

Re: Posix file capabilities in 2.6.24rc2

2007-11-14 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello Serge, I wanted only to express what I observed. A yes it should confirms its ok. And yes, I haven't looked into the patches and the name and commentary of file-capabilities-clear-fcaps-on-inode-change.patch explains this already. I'm

Re: Posix file capabilities in 2.6.24rc2

2007-11-13 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): > Hello, > > everything works as expected, but ... > > closing X and no capabilities set for xinit does shutdown only the > windowmanager and not the X server (Xorg server 1.4) > Consolemessage is: > xinit: Operation not permitted (errno 1): Can't

Posix file capabilities in 2.6.24rc2

2007-11-13 Thread Chris Friedhoff
Hello, everything works as expected, but ... closing X and no capabilities set for xinit does shutdown only the windowmanager and not the X server (Xorg server 1.4) Consolemessage is: xinit: Operation not permitted (errno 1): Can't kill X server the xattr capability is removed, when the file

Posix file capabilities in 2.6.24rc2

2007-11-13 Thread Chris Friedhoff
Hello, everything works as expected, but ... closing X and no capabilities set for xinit does shutdown only the windowmanager and not the X server (Xorg server 1.4) Consolemessage is: xinit: Operation not permitted (errno 1): Can't kill X server the xattr capability is removed, when the file

Re: Posix file capabilities in 2.6.24rc2

2007-11-13 Thread Serge E. Hallyn
Quoting Chris Friedhoff ([EMAIL PROTECTED]): Hello, everything works as expected, but ... closing X and no capabilities set for xinit does shutdown only the windowmanager and not the X server (Xorg server 1.4) Consolemessage is: xinit: Operation not permitted (errno 1): Can't kill X