Article 4YNHK idea: why not to use posix acl (file permissions) to restrict apps?

idea: why not to use posix acl (file permissions) to restrict apps?

by
qdinar
from LinuxQuestions.org on (#4YNHK)
i have seen apparmor profiles, and they mainly consist of file paths and read, write, execute permissions. this seems duplicating usual file/path permissions of linux/unix (posix acl). why not just use that usual permission system instead of apparmor/suexec? daemons/servers like apache, mysql are running with their own user. so, every app can be given its own user. then a problem appear: files saved by different human users with same app will have same owner, so will be accessible by other human users, other than who really saved it, using same app. maybe there is a way to make them not accessible, maybe tweaking user (owner) and group permissions of home folders, addng app and human users to some groups...latest?d=yIl2AUoC8zA latest?i=n7e8NNhF430:9p0TRxcZJzI:F7zBnMy latest?i=n7e8NNhF430:9p0TRxcZJzI:V_sGLiP latest?d=qj6IDK7rITs latest?i=n7e8NNhF430:9p0TRxcZJzI:gIN9vFwn7e8NNhF430
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments