Thread (1 message) flat view 1 message, 1 author, 2017-10-21

Re: [RFC PATCH 1/2] security, capabilities: create CAP_TRUSTED

From: "Serge E. Hallyn" <serge@hallyn.com>
Date: 2017-10-21 16:03:04
Also in: linux-ext4, linux-f2fs-devel, linux-fsdevel, linux-security-module, linux-unionfs, lkml, selinux

Quoting Nicolas Belouin (nicolas@belouin.fr):
with CAP_SYS_ADMIN being bloated, the usefulness of using it to
flag a process to be entrusted for e.g reading and writing trusted
xattr is near zero.
CAP_TRUSTED aims to provide userland with a way to mark a process as
entrusted to do specific (not specially admin-centered) actions. It
would for example allow a process to red/write the trusted xattrs.
You say "for example".  Are you intending to add more uses?  If so, what
are they?  If not, how about renaming it CAP_TRUSTED_XATTR?

What all does allowing writes to trusted xattrs give you?  There are
the overlayfs whiteouts, what else?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help