privileges

Gunther Mayer gunther.mayer at googlemail.com
Tue Feb 3 14:57:42 UTC 2009


Daniel Berteaud wrote:
> Le samedi 31 janvier 2009 à 11:28 +0100, David Bird a écrit :
>   
>> Options for uid and gid will be in the next svn update, most likely.
>>     

I can see many issues already with running chilli as non-root: For 
example how should uamanyip create any routes for new static ip clients? 
Also I'm sure there are certain IOCTL's in tun.c which might not take 
lightly to being accessed by an unprivileged user. I think properly 
securing this is a lot more work than it seems... But then again David's 
our man and if he can't do it no-one can ;-)

Gunther



More information about the Chilli mailing list