FW: Re: pre-compiled systemtap modules - try2 feature request

Frank Ch. Eigler fche@redhat.com
Mon Sep 18 12:43:00 GMT 2006


Hi, David -

> > We are aware of this need, and work is in progress as we speak to
> > promote this style of usage.  Do you have any suggestions about what
> > form the "blessings" might have?
> 
> For the next couple of years the security blessing is fairly simple. The
> user cannot have root access to the file system, capture or read other users
> passwords, impersonate another user, or bypass kernel auditing.  [...]

What I meant to ask was whether you had any thoughts about how such
blessing (permission to run some particular systemtap script) might be
encoded into software.

- FChE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://sourceware.org/pipermail/systemtap/attachments/20060918/4ab7b74f/attachment.sig>


More information about the Systemtap mailing list