Re: AUTH

Jens Kasten <[email protected]>
Newsgroups gmane.linux.rsbac
Message-ID <1332999757.6964.3.camel@jaschtschik-pc>
Am Donnerstag, den 29.03.2012, 08:28 +0200 schrieb Lorenzo Marcantonio:
> On Thu, Mar 29, 2012 at 06:28:00AM +0200, Jens Kasten wrote:
> > Mar 29 05:20:54 jaschtschik-pc kernel: 0000001371|rsbac_adf_request():
> > request CHANGE_OWNER, pid 3859, ppid 3858, prog_name strace,
> > prog_file /usr/bin/strace, uid 1000, target_type PROCESS, tid
> > 3859(strace,parent=3858(strace)), attr owner, value 1000, result
> > NOT_GRANTED by AUTH
> > 
> > I got a result from strace.
> > It should be terminated.
> 
> Why? it tried to setuid itself to the old owner and it wasn't listed
> in its AUTH capabilies..
I think if AUTH say no, than its have to be.

> If you want to suppress these 'spurious' AUTH failures there is a build
> option: in the AUTH policy support check the 'Always allow setting to
> the same id'
This option I don't have set.

> 
> I agree that it may seems stupid but I suspect there is a formal reason
> for this behaviour
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.