commons-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From jean-frederic clere <>
Subject [daemon] Threads and setuid on Linux
Date Mon, 25 Feb 2002 11:42:41 GMT

I have noted a small problem when using the daemon on Linux.
The jsvc starts several threads when he is root but the Linux setuid only
applies on the current thread so the software ends into various threads
belonging to root and others to nobody. :-(

I have tried to solve the problem making the setuid before the loading the JVM
(java_init) but keeping some root capabilities till after the loading of the
service (java_load).

The idea is do the following (only with using linux):

setcapabilities via syscall
using prctl to be able to set them after the setuid/getid.
setuid and getid.
load JVM (java_init).
load the service (java_load).
setcapabilities to minimum (CAP_NET_BIND_SERVICE?).

Any comments?



To unsubscribe, e-mail:   <>
For additional commands, e-mail: <>

View raw message