Browse code

Use SETUID root for contain.

YustasSwamp authored on 2015/07/07 01:19:33
Showing 1 changed files
... ...
@@ -314,7 +314,8 @@ $(TOOLS_BIN):
314 314
 	mkdir -p $(TOOLS_BIN)
315 315
 
316 316
 $(CONTAIN): $(TOOLS_BIN)
317
-	gcc -O2 -std=gnu99 -Wall -Wextra $(SRCROOT)/tools/src/contain/*.c -o $@
317
+	gcc -O2 -std=gnu99 -Wall -Wextra $(SRCROOT)/tools/src/contain/*.c -o $@_unpriv
318
+	sudo install -o root -g root -m 4755 $@_unpriv $@
318 319
 
319 320
 sha1:
320 321
 	@cd $(PHOTON_SRCS_DIR) && \