The trouble with dropping groups
The trouble with dropping groups
Posted Nov 20, 2014 1:38 UTC (Thu) by skissane (subscriber, #38675)Parent article: The trouble with dropping groups
What about a flag on a group which says it is allowed to be dropped by an unprivileged process? By default, that flag would not be enabled for any group, but sysadmin could enable it on a group-by-group basis. That would likely be much safer than an across-the-board sysctl knob.