[syslog-ng] 2.6.38: CAP_SYSLOG

Gergely Nagy algernon at balabit.hu
Tue Feb 1 18:20:14 CET 2011


On Tue, 2011-02-01 at 18:34 +0200, Sergey Senozhatsky wrote: 
> Hello,
> 
> During 2.6.38 development CAP_SYSLOG has been introduced to perform syslog 
> operations, older CAP_SYS_ADMIN is not sufficient anymore.

It's a known issue, but no suitable solution (that doesn't break in
interesting ways under pressure) has been found yet.

Since CAP_SYSLOG breaks userspace, I'm hoping that this will be reverted
before the 2.6.38 release. Though, looking at recent lkml traffic, I'll
have to Cc a few more people regarding the issue.

-- 
|8]





More information about the syslog-ng mailing list