|
|
|
Re: [PATCH v17 01/15] Add PR_{GET,SET}_NO_NEW_PRIVS to prevent execve from granting privs | |
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] | |
On Thu, 29 Mar 2012 15:01:46 -0500 Will Drewry <wad@xxxxxxxxxxxx> wrote: > From: Andy Lutomirski <luto@xxxxxxxxxxxxxx> > > With this set, a lot of dangerous operations (chroot, unshare, etc) > become a lot less dangerous because there is no possibility of > subverting privileged binaries. The changelog doesn't explain the semantics of the new syscall. There's a comment way-down-there which I guess suffices, if you hunt for it. And the changelog doesn't explain why this is being added. Presumably seccomp_filter wants/needs this feature but whowhatwherewhenwhy? Spell it all out, please. The new syscall mode will be documented in the prctl manpage. Please cc linux-man@xxxxxxxxxxxxxxx and work with Michael on getting this done? > > ... > -- To unsubscribe from this list: send the line "unsubscribe linux-doc" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html
[Site Home] [Kernel Newbies] [Share Photos] [Security] [Netfilter] [Bugtraq] [Linux FS] [Photo] [Yosemite] [Yosemite News] [MIPS Linux] [ARM Linux] [Linux Security] [Linux RAID] [Samba] [Video 4 Linux] [Device Mapper] [Linux Resources]
![]() |