The intention of Trusted Extended Attributes is for processes that
perform tasks that are relevant for the proper functioning of the
system, to allow them to use EAs. Other, non-privileged processes shall
have no access whatsoever to those EAs. This level of protection would
otherwise only be possible by providing a kernel module.
I would be quite happy with a new CAP_TRUSTED_PROCESS or whatever, but
going that route for all sorts of applications then we might soon end
up with an large number of capabilities. Maybe I'm wrong on that,
though.
Cheers,
Andreas.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/