Re: access to /dev/mem
Posted Jul 22, 2005 1:47 UTC (Fri) by
sweikart (guest, #4276)
In reply to:
The ExecShield patches by dlang
Parent article:
Kernel Summit 2005: The ExecShield patches
Here's a good description of it:
http://lwn.net/1999/1202/kernel.php3
And here's an implementation for dropping capabilities at boot time:
http://lists.nas.nasa.gov/archives/ext/linux-security-aud...
Since you can disable access to /dev/mem with the capability bounding set, I would request that the semantics of /dev/mem not change.
-scott
(
Log in to post comments)