[hipl-users] Re: reducing hipd privileges

  • From: Joakim Koskela <joakim.koskela@xxxxxxx>
  • To: hipl-users@xxxxxxxxxxxxx
  • Date: Fri, 17 Aug 2007 16:14:25 +0300

Sorry for that, was ment to go private

On Friday 17 August 2007 16:11:09 Joakim Koskela wrote:
> tuli tällänen kun käynnistää hipd:
>
> <snip>
> debug(cookie.c:302@hip_precreate_r1): Packet 2 created
> debug(netdev.c:819@hip_add_iface_local_route): Adding local HIT route:
> 2001:0012:6bb3:200d:1501:82d2:ccac:c453/128
> debug(nlink.c:535@hip_iproute_modify): Setting
> 2001:0012:6bb3:200d:1501:82d2:ccac:c453/128 as route for dummy0 device with
> family 10 debug(netdev.c:783@hip_add_iface_local_hit): Adding HIT:
> 2001:0012:6bb3:200d:1501:82d2:ccac:c453/28
> debug(nlink.c:687@hip_ipaddr_modify): IP got
> 2001:0012:6bb3:200d:1501:82d2:ccac:c453/28
> debug(hidb.c:339@hip_handle_add_local_hi): Adding of HIP localhost
> identities was successful debug(init.c:326@hip_set_lowcapability): Now
> PR_SET_KEEPCAPS=1
> debug(init.c:335@hip_set_lowcapability): CAPABILITY value is 
> effective=4294967039, permitted = 4294967295, inheritable=0
> debug(init.c:339@hip_set_lowcapability): Before setreuid(,) UID=0 and
> EFF_UID=0 debug(init.c:343@hip_set_lowcapability): After setreuid(,)
> UID=65534 and EFF_UID=65534 debug(init.c:348@hip_set_lowcapability):
> CAPABILITY value is  effective=0, permitted = 0, inheritable=0
> debug(init.c:349@hip_set_lowcapability): We are going to clear all
> capabilities except the ones we need:
> error(init.c:359@hip_set_lowcapability): error while setting new
> capabilities through 'capset()' error(init.c:304@hipd_init): Failed to set
> capabilities
> error(hipd.c:331@main): hipd_init() failed!
> error(init.c:555@hip_exit): Signal: 1
> debug(hadb.c:2294@hip_delete_all_sp):
> debug(hadb.c:2296@hip_delete_all_sp): DEBUG: DUMP SPI LISTS
> debug(hadb.c:2306@hip_delete_all_sp): DELETING HA HT
> debug(netdev.c:282@delete_all_addresses): address_count at entry=4
> error(nlink.c:752@do_chflags): SIOCSIFFLAGS Permission denied
> debug(nlink.c:774@set_up_device): setting dummy0 done
> debug(hadb.c:2261@hip_uninit_hadb):
> debug(hadb.c:2263@hip_uninit_hadb): DEBUG: DUMP SPI LISTS
> info(hipd.c:610@main): hipd pid=15909 exiting, retval=1
>
> t. j



-- 
Joakim Koskela
Helsinki Institute for Information Technology (HIIT)
email: joakim.koskela@xxxxxxx
mobile: +358 50 5459786

Other related posts: