lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <169280342168.26154.6028605816933015881.git-patchwork-notify@kernel.org> Date: Wed, 23 Aug 2023 15:10:21 +0000 From: patchwork-bot+netdevbpf@...nel.org To: Maximilian Bosch <maximilian@...sch.me> Cc: netdev@...r.kernel.org Subject: Re: [PATCH iproute2-next v2] ip-vrf: recommend using CAP_BPF rather than CAP_SYS_ADMIN Hello: This patch was applied to iproute2/iproute2.git (main) by Stephen Hemminger <stephen@...workplumber.org>: On Tue, 22 Aug 2023 14:33:07 +0200 you wrote: > The CAP_SYS_ADMIN capability allows far too much, to quote > `capabilities(7)`: > > Note: this capability is overloaded; see Notes to kernel developers, below. > > In the case of `ip-vrf(8)` this is needed to load a BPF program. > According to the same section of the same man-page, using `CAP_BPF` is > preferred if that's the reason for `CAP_SYS_ADMIN`; > > [...] Here is the summary with links: - [iproute2-next,v2] ip-vrf: recommend using CAP_BPF rather than CAP_SYS_ADMIN https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/commit/?id=df210e83e0fa You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html
Powered by blists - more mailing lists