On Tue, 2008-09-30 at 11:28 -0500, Serge E. Hallyn wrote:
A capability that they cannot possibly have since it doesn't exist :)
No argument from me that patching up for buggy drivers sucks. Yours
would be less overhead, and it would return the cap system back to
pre-2.6.25 operation (garbage in garbage out but no panic). Since we
already have the branch in SELinux its no 'extra' overhead to EPERM
there instead of here (garbage in EPERM out).
-Eric
--