reminder: "POSIX capabilities" are different from "capabilities"
Posted May 13, 2004 23:44 UTC (Thu) by
pimlott (guest, #1535)
In reply to:
reminder: "POSIX capabilities" are different from "capabilities" by rjw
Parent article:
Magic groups in 2.6
We should also be careful to separate the concept of a physical user from a unix uid. Users should have the ability to create subservient users and groups - that are bounded by the permission set that their 'principal' user has.
Oh man, I wish someone had done this. Now that we have SELinux et al, it's not likely to happen.
SELinux really makes me sick.
*rech*
(
Log in to post comments)