Re: vserver LSM progress

About this list Date view Thread view Subject view Author view Attachment view

From: Chris Wright (chris_at_wirex.com)
Date: Fri Oct 26 2001 - 03:07:46 EDT


* Kyle Hayes (khayes_at_quicknet.net) wrote:
> It is increasingly possible to do things to the kernel and to the system as a
> whole through proc interfaces. How can that be controlled?

/proc is a filesystem. since lsm easily controls all access to files
(and filesystems) this is how you control it. and i'd think it should
behave like vserver's sysctl interface.

> Do the capability sets allow me to control access to the /proc file such that
> a chrooted vserver "root" user cannot stop IP forwarding for instance? I do
> not understand all the things that can be controlled via these capability
> bits, so please bear with my newbie questions :-)

this depends on the /proc entry. it is a combination of file
permissions and capabilities.

-chris


About this list Date view Thread view Subject view Author view Attachment view

This archive was generated by hypermail 2.1.4 : Mon Aug 19 2002 - 12:01:00 EDT