COMPARTMENT(1) | General Commands Manual | COMPARTMENT(1) |
compartment - secure program/service wrapper
compartment [--cap CAPSET] [--chroot PATH] [--user USER] [--group GROUP] [--init PROGRAM] [--verbose] [--quiet] [--fork] /full/path/to/program
The Secure Compartment was designed to allow safe execution of priviliged and/or untrusted executables and services. It has got all features possible included, which can be used to minimize the risk of a trojanized or vulnerable program/service.
Linux Capabilities
Chrooting
Privileges
Setup Scripts
Currently the kernel does not allow capabilities on processes which are not running with euid 0. Therefore compartment will exit with an error if --user and --cap is used together.
Please note that this will change for the 2.4 kernel.
No bugs are currently known
Marc Heuse <marc@suse.de>
compartment is part of the SuSE Linux Distribtution since 7.0 so it can be downloaded as an RPM file from the SuSE FTP servers. It can also be downloaded as a .tar.gz file from http://www.suse.de/~marc
It has been also part of the Debian GNU/Linux distribution since just after woody (Debian 3.0)
This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; Version 2.
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
capset (2), chroot (1), chroot (2)