Navigation
Recherche
|
[$] Inheritable credentials for directory file descriptors
jeudi 2 mai 2024, 17:10 , par LWN.net
In Unix-like systems, an open file descriptor carries the right to access
the opened object in specific ways. As a general rule, that file descriptor does not enable access to any other objects. The recently merged BPF token feature runs counter to this practice by creating file descriptors that carry specific BPF-related access rights. A similar but different approach to capability-carrying file descriptors, in the form of directory file descriptors that include their own credentials, is currently under consideration in the kernel community.
https://lwn.net/Articles/971825/
|
56 sources (32 en français)
Date Actuelle
dim. 24 nov. - 19:07 CET
|