[PATCH 01/12] Security: Add CAP_COMPROMISE_KERNEL
James Morris
jmorris at namei.org
Wed Mar 20 21:58:04 EDT 2013
On Wed, 20 Mar 2013, Mimi Zohar wrote:
> On Tue, 2013-03-19 at 15:47 +1100, James Morris wrote:
> > On Mon, 18 Mar 2013, Matthew Garrett wrote:
> >
> > > This patch introduces CAP_COMPROMISE_KERNEL.
> >
> > I'd like to see this named CAP_MODIFY_KERNEL, which is more accurate and
> > less emotive. Otherwise I think core kernel developers will be scratching
> > their head over where to sprinkle this.
> >
> > Apart from that, I like the idea, especially when it's wired up to MAC
> > security.
>
> Matthrew, perhaps you could clarify whether this will be tied to MAC
> security.
All capabilities are, via LSM.
--
James Morris
<jmorris at namei.org>
More information about the kexec
mailing list