netdev
[Top] [All Lists]

Re: disablenetwork() syscall?

To: Pekka Savola <pekkas@xxxxxxxxxx>
Subject: Re: disablenetwork() syscall?
From: Mitchell Blank Jr <mitch@xxxxxxxxxx>
Date: Mon, 7 Jul 2003 14:03:10 -0700
Cc: netdev@xxxxxxxxxxx
In-reply-to: <Pine.LNX.4.44.0307072237560.11843-100000@xxxxxxxxxx>
References: <Pine.LNX.4.44.0307072237560.11843-100000@xxxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.4.1i
Pekka Savola wrote:
> In a bugtraq thread, DJ Bernstein brought up an idea which I'm not sure 
> has been brought up in the past.  I'm not sure whether it's feasible or 
> not, but at least it (and other methods to limit the functions of a 
> user-level code) might bear consideration.

It sounds like something that could be a implemented as a capability
(CAP_NET_ACCESS or such)

-Mitch

<Prev in Thread] Current Thread [Next in Thread>