File: compartment.1

package info (click to toggle)
compartment 1.3-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 208 kB
  • sloc: ansic: 1,095; makefile: 99
file content (123 lines) | stat: -rw-r--r-- 2,650 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
.de Sp
.if n .sp
.if t .sp 0.4
..
.TH COMPARTMENT 1

.SH NAME
compartment \- secure program/service wrapper

.SH SYNOPSIS
.B compartment [--cap CAPSET] [--chroot PATH] [--user USER] [--group GROUP] [--init PROGRAM] [--verbose] [--quiet] [--fork] /full/path/to/program

.SH DESCRIPTION
The
.I Secure Compartment 
was designed to allow safe execution of priviliged and/or untrusted executables and services.
It has got all features possible included, which can be used to minimize the risk of a trojanized or vulnerable program/service.

.SH COMMANDLINE OPTIONS
.PP
.TP
.B \--cap CAPSET
sets the defined
.I CAPABILITY
for the process.
See the README file for more information and examples.

.PP
.TP
.B \--chroot PATH
.I chroots
to the PATH defined. It has to be a valid chroot environment.
See the README file for more information and examples.

.PP
.TP
.B \--user USER
runs the program with uid/euid of USER

.PP
.TP
.B \--group GROUP
runs the program with gid/egid of GROUP

.PP
.TP
.B \--init PROGRAM
runs PROGRAM before running the untrusted program/service, e.g. to build a chroot environment

.PP
.TP
.B \--verbose
prints detailled information what
.I compartment
does.

.PP
.TP
.B \--quit
does not print syslog information about the use of
.I compartment

.PP
.TP
.B \--fork
forks if everything was set up correctly, mother process will exit.

.SH FEATURES
.PP
.I Linux Capabilities
.TP
.B supports all Linux capabilites
(see /usr/include/linux/capability.h and the README file)
.PP
.I Chrooting
.TP
.B supports a chroot setup
.PP
.I Privileges
.TP
.B supports running with defined user and/or group privileges
.PP
.I Setup Scripts
.TP
.B supports running of initial scripts
before running a program/service, e.g. to build a chroot environment.

.SH BUGS
No bugs are currently known

.SH AUTHOR
.Sp
Marc Heuse
.I <marc@suse.de> 

.SH DISTRIBUTION
.I compartment
is part of the SuSE Linux Distribtution since 7.0 so it can be downloaded as
an RPM file from the SuSE FTP servers. It can also be downloaded as a .tar.gz
file from
.I http://www.suse.de/~marc
.PP
It has been also part of the Debian GNU/Linux distribution since just
after woody (Debian 3.0)

.SH LICENCE
.Sp
This program is free software; you can redistribute it and/or modify it
under the terms of the GNU General Public License as published by the Free
Software Foundation; Version 2.
.Sp
This program is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
for more details.

.SH SEE ALSO
.I capset
(2),
.I chroot
(1),
.I chroot
(2)