3 ms·
(and not just "secure" as in security, but also "secure" as in fixed-interface)
by fche 11y ago
(and not just "secure" as in security, but also "secure" as in fixed-interface)
- monocasa 11y agoYeah, totally. It needs more time to bake in general. I was just mainly referring to the fact that it's current requirement of CAP_SYS_ADMIN is kind of a non starter for more general use at the moment.
- fche 11y agoGiven that the bytecode system can at least read arbitrary kernel memory, it better be CAP_SYS_ADMIN due to information disclosure alone.
- monocasa 11y agoYeah, in it's current form it absolutely should require CAP_SYS_ADMIN. A restricted subset (and probably some extensions) would be required to remove that requirement. There's a lot of benefit though to doing that work. Think AIO programs that kick off new work on completion kind of like s/360 channel programs. Or emulation of regular devices that approaches the speed of para virtualized devices in KVM. But you need to find a (safe) way to allow non privileged users to access this functionality for this to make sense.