Searched refs:no_new_privs (Results 1 – 6 of 6) sorted by relevance
4 :Original: Documentation/userspace-api/no_new_privs.rst25 这些都是临时性的修复。 ``no_new_privs`` 位(从 Linux 3.5 起)是一个新的通27 置 ``no_new_privs`` 。一旦该位被设置,它会在fork、clone和execve中继承下去28 ,并且不能被撤销。在 ``no_new_privs`` 被设置的情况下, ``execve()`` 将保证33 设置 ``no_new_privs`` 使用::37 不过要小心,Linux安全模块(LSM)也可能不会在 ``no_new_privs`` 模式下收紧约束。38 (这意味着一个一般的服务启动器在执行守护进程前就去设置 ``no_new_privs`` 可能44 目前来说, ``no_new_privs`` 有两大使用场景:47 非特权用户因此在 ``no_new_privs`` 被设置的情况下只允许安装这样的过滤器。49 - ``no_new_privs`` 本身就能被用于减少非特权用户的攻击面。如果所有以某个 uid[all …]
27 no_new_privs
21 These are all ad-hoc fixes. The ``no_new_privs`` bit (since Linux 3.5) is a32 To set ``no_new_privs``, use::37 in ``no_new_privs`` mode. (This means that setting up a general-purpose38 service launcher to set ``no_new_privs`` before execing daemons may41 Note that ``no_new_privs`` does not prevent privilege changes that do not45 There are two main use cases for ``no_new_privs`` so far:50 if ``no_new_privs`` is set.52 - By itself, ``no_new_privs`` can be used to reduce the attack surface54 given uid has ``no_new_privs`` set, then that uid will be unable to57 ``no_new_privs`` bit set first.[all …]
19 no_new_privs
1812 TASK_PFA_TEST(NO_NEW_PRIVS, no_new_privs) in TASK_PFA_TEST() argument1813 TASK_PFA_SET(NO_NEW_PRIVS, no_new_privs) in TASK_PFA_TEST()
295 NoNewPrivs no_new_privs, like prctl(PR_GET_NO_NEW_PRIV, ...)
Completed in 16 milliseconds