Skip to content
Commit 91389f87 authored by Pavel Emelyanov's avatar Pavel Emelyanov
Browse files

security: Introduce (rather basic) security restrictions for C/R



Right now we have an ability to launch the C/R service from root
and execure dump requests from unpriviledged users. Not to be bad
guys, we deny dumping tasks belonging to user, that cannot be
"watched" (traced, read /proc, etc.) by the dumper.

In the future we will use this "engine" when launched with suid
bit, and (probably) will have more sophisticated policy.

Signed-off-by: default avatarPavel Emelyanov <xemul@parallels.com>
parent cfe72ab7
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment