Gentoo Archives: gentoo-dev

From: "vivo75@×××××.com" <vivo75@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] RFC: iotop needs to run as root after kernel change
Date: Wed, 04 Apr 2012 10:02:43
Message-Id: 4F7C1C09.8040605@gmail.com
In Reply to: Re: [gentoo-dev] RFC: iotop needs to run as root after kernel change by "Paweł Hajdan
1 Il 04/04/2012 08:43, "Paweł Hajdan, Jr." ha scritto:
2 > On 4/4/12 8:32 AM, justin wrote:
3 >> 1.
4 >> Leave it to root (Fedora and Suses way)
5 > I think that's the best option, at least for now.
6 >
7 >> 2.
8 >> suid it (bad in my view)
9 > Agreed, that'd be very bad, any crashing bug in it could become a
10 > privilege escalation problem.
11 >
12 >> 3.
13 >> file capabilities (can this be done with portage)
14 > Slightly better than the above, but I still prefer #1.
15
16 Or default to 1. but provide a use flag to achieve 3.
17 net-wireless/kismet uses 'suid', maybe other use 'caps' use flags?
18 Hopefully others can answer on how to apply capabilities to executables