3 ms·
A potential solution is to create a user who has no or limited write access, and modify up so that it always switches to that user. I wonder if there’s a way t
by slewis 8y ago
A potential solution is to create a user who has no or limited write access, and modify up so that it always switches to that user.
I wonder if there’s a way to do this without requiring the creation of a new system user. Some way to revoke all write access for the current process.
- dharmab 8y agoCapabilities do this. It's the same mechanic used by containers to restrict their access. See man capabilities(7)
- drb91 8y agoSeems to be linux only at first blush.
- akavel 8y agoI'm ok with focusing on Linux as the prime target for up. Though I'm totally trying to think about cross-platform approaches too, obviously.
- codetrotter 8y agoFreeBSD has a capabilities system called “Capsicum”. https://www.freebsd.org/cgi/man.cgi?capsicum(4) https://www.freebsd.org/cgi/man.cgi?capsicum(4) https://wiki.freebsd.org/Capsicum https://wiki.freebsd.org/Capsicum https://www.cl.cam.ac.uk/research/security/capsicum/freebsd.html https://www.cl.cam.ac.uk/research/security/capsicum/freebsd.... Capsicum is convoluted though. OpenBSD has pledge and unveil, which from what I have seen are very elegant. https://man.openbsd.org/pledge.2 https://man.openbsd.org/pledge.2 https://man.openbsd.org/unveil https://man.openbsd.org/unveil
- deleted 8y ago[deleted]