Gentoo Archives: gentoo-dev

From: Duncan <1i5t5.duncan@×××.net>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: fcaps.eclass: bringing filesystem capabilities to the tree
Date: Sat, 26 Jan 2013 10:17:46
Message-Id: pan.2013.01.26.10.17.18@cox.net
In Reply to: Re: [gentoo-dev] fcaps.eclass: bringing filesystem capabilities to the tree by Mike Frysinger
1 Mike Frysinger posted on Sat, 26 Jan 2013 02:46:12 -0500 as excerpted:
2
3 > if the package supports USE=caps, then it means the program is
4 > intelligent enough to know what capabilities it needs and so it can drop
5 > all of the rest before executing the main body of code.
6
7 > wouldn't it be nice if you could set the required capabilities on a
8 > binary and drop the set*id entirely ? that's what USE=filecaps gets us.
9
10 Very useful summary. Thanks. =:^)
11
12 I had all the pieces from various reading, but they were more in a heap
13 than assembled, and just the other day I was trying to assemble them into
14 something coherent (triggered by this thread, IIRC), but discovered I
15 still needed a bit of help. This was exactly what I needed for the
16 accumulated information to all fall into place! Thanks again! =:^)
17
18 --
19 Duncan - List replies preferred. No HTML msgs.
20 "Every nonfree program has a lord, a master --
21 and if you use the program, he is your master." Richard Stallman