3 ms·
Given that the bytecode system can at least read arbitrary kernel memory, it better be CAP_SYS_ADMIN due to information disclosure alone.
by fche 11y ago
Given that the bytecode system can at least read arbitrary kernel memory, it better be CAP_SYS_ADMIN due to information disclosure alone.
- monocasa 11y agoYeah, in it's current form it absolutely should require CAP_SYS_ADMIN. A restricted subset (and probably some extensions) would be required to remove that requirement. There's a lot of benefit though to doing that work. Think AIO programs that kick off new work on completion kind of like s/360 channel programs. Or emulation of regular devices that approaches the speed of para virtualized devices in KVM. But you need to find a (safe) way to allow non privileged users to access this functionality for this to make sense.