On Mon, 2013-09-09 at 09:51 -0700, H. Peter Anvin wrote: > On 09/09/2013 09:44 AM, Matthew Garrett wrote: > > On Mon, 2013-09-09 at 09:42 -0700, H. Peter Anvin wrote: > > > >> Neither of this tend to be true long time... which leads one back to > >> capabilities. > > > > We can't use capabilities. Doing so breaks existing userspace. > > > > Capabilities don't have to mean "POSIX capabilities"... although the > POSIX capability system in Linux really is a massive fail which it would > be nice to find some kind of fix for. Designing a worthwhile capabilities interface certainly seems like a great thing for someone to spend a few years on, but I'm not going to be happy if it's the only way to solve this problem. -- Matthew Garrett <matthew.garrett@xxxxxxxxxx> ��.n��������+%������w��{.n�����{����*jg��������ݢj����G�������j:+v���w�m������w�������h�����٥