Re: [RFC PATCH 1/2] security, capabilities: create CAP_TRUSTED

[email protected]
Newsgroups gmane.comp.file-systems.jfs.general
Message-ID <201710211909.v9LJ9Zg8033866__41234.1358293363$1508644649$gmane$org@smtp6.infomaniak.ch>
<[email protected]>,[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected],[email protected]
From: Nicolas Belouin <[email protected]>
Message-ID: <[email protected]>



On October 21, 2017 6:03:02 PM GMT+02:00, "Serge E. Hallyn" <[email protected]> wrote:
>Quoting Nicolas Belouin ([email protected]):
>> with CAP_SYS_ADMIN being bloated, the usefulness of using it to
>> flag a process to be entrusted for e.g reading and writing trusted
>> xattr is near zero.
>> CAP_TRUSTED aims to provide userland with a way to mark a process as
>> entrusted to do specific (not specially admin-centered) actions. It
>> would for example allow a process to red/write the trusted xattrs.
>
>You say "for example".  Are you intending to add more uses?  If so,
>what
>are they?  If not, how about renaming it CAP_TRUSTED_XATTR?
>

I don't see any other use for now, but I don't want it to be too narrow and non usable in a similar context in the future. So I believe the underlying purpose of marking a process as "trusted" (even if for now it only means rw permission on trusted xattr) is more meaningful.

>What all does allowing writes to trusted xattrs give you?  There are
>the overlayfs whiteouts, what else?

Nicolas

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.