On 2005.04.15 20:49:08 +0200, Dominik Dausch wrote:
> Hi,
> 
> i have compiled a 2.6.11.5 with vserver patch applied. Herberts
> testme.sh gives the following output:
> 
> Linux-VServer Test [V0.11] (C) 2003-2005 H.Poetzl
> chcontext is working.
> chbind is working.
> Linux 2.6.11.5-vs1.9.5 i686/0.30.206/0.30.206 [Ea]
> VCI:  0001:0025 273 03000016
> ---
> [001]# succeeded.
> [011]# failed.
> [031]# succeeded.
> [101]# succeeded.
> [102]# succeeded.
> [201]# succeeded.
> [202]# succeeded.
> 
> And a newly created debian sarge vserver says the following if i try
> to start it:
> 
> capset(): Operation not permitted
> capabilities are not enabled in kernel-setup

You enabled CONFIG_SECURITY but not CONFIG_SECURITY_CAPABILITIES (or at
least you built the latter as a module and didn't load it).
You're choices are:
(a) Disable CONFIG_SECURITY
(b) Have CONFIG_SECURITY_CAPABILITES built-in
(c) Load the capabilities module (as early as possible)

If you really want to go with (c), i suggest you take a look at the debian
kernels and their way of loading that module. Maybe make-kpkg takes care
of such stuff when you built your own kernel, but i've never tried that,
i always go for (a).

HTH
Bjoern
_______________________________________________
Vserver mailing list
[email protected]
http://list.linux-vserver.org/mailman/listinfo/vserver

Reply via email to