LWN.net Logo

CAP_SYS_ADMIN: the new root

CAP_SYS_ADMIN: the new root

Posted Mar 14, 2012 21:22 UTC (Wed) by ballombe (subscriber, #9523)
Parent article: CAP_SYS_ADMIN: the new root

Maybe an extra level of indirection would help:
Linux developers would create new virtual capabilities for each new usages,
and the capabilities maintainer would associate them to real capabilities
in separate patches.


(Log in to post comments)

CAP_SYS_ADMIN: the new root

Posted Mar 15, 2012 20:05 UTC (Thu) by bronson (subscriber, #4806) [Link]

That might help but I'd be afraid that it opens another attack surface. A virtual capability may appear safe, but mapping it to a real capability could cause rather nonobvious holes to appear. Especially if multiple virtual capabilities get mapped into a single real one.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds