Re: [vserver] I'd like to --move it --move it

From: Ben Green <ben_at_bristolwireless.net>
Date: Mon 13 Dec 2010 - 09:07:39 GMT
Message-ID: <20101213090739.74925tj88o1rptvk@slackmail.co.uk>

Quoting "Jon Bendtsen" <jbendtsen@laerdal.dk>:

>>
>> Is there some kind of flag I can set to make this work? What else
>> should I try?
>
> danger! alert! security risk!
>
> If you give your guest the mount capability then I am sure it can do
> what you want to do.
>

Don't be so sure! The server has long time had a number of insecure
settings crucial for LTSP operation, ccaps:

BINARY_MOUNT
SECURE_MOUNT
SECURE_REMOUNT
SET_UTSNAME
RAW_ICMP
SYSLOG
NAMESPACE
FS_SECURITY

And bcaps:

NET_RAW
MKNOD

I think MKNOD is removable now, but was need for building the LTSP chroot.

Cheers,
==
 From Ben Green

Received on Mon Dec 13 09:07:48 2010
[Next/Previous Months] [Main vserver Project Homepage] [Howto Subscribe/Unsubscribe] [Paul Sladen's vserver stuff]
Generated on Mon 13 Dec 2010 - 09:07:48 GMT by hypermail 2.1.8