On 2005.04.15 20:49:08 +0200, Dominik Dausch wrote: > Hi, > > i have compiled a 2.6.11.5 with vserver patch applied. Herberts > testme.sh gives the following output: > > Linux-VServer Test [V0.11] (C) 2003-2005 H.Poetzl > chcontext is working. > chbind is working. > Linux 2.6.11.5-vs1.9.5 i686/0.30.206/0.30.206 [Ea] > VCI: 0001:0025 273 03000016 > --- > [001]# succeeded. > [011]# failed. > [031]# succeeded. > [101]# succeeded. > [102]# succeeded. > [201]# succeeded. > [202]# succeeded. > > And a newly created debian sarge vserver says the following if i try > to start it: > > capset(): Operation not permitted > capabilities are not enabled in kernel-setup
You enabled CONFIG_SECURITY but not CONFIG_SECURITY_CAPABILITIES (or at least you built the latter as a module and didn't load it). You're choices are: (a) Disable CONFIG_SECURITY (b) Have CONFIG_SECURITY_CAPABILITES built-in (c) Load the capabilities module (as early as possible) If you really want to go with (c), i suggest you take a look at the debian kernels and their way of loading that module. Maybe make-kpkg takes care of such stuff when you built your own kernel, but i've never tried that, i always go for (a). HTH Bjoern _______________________________________________ Vserver mailing list [email protected] http://list.linux-vserver.org/mailman/listinfo/vserver
