View Single Post
Posts: 245 | Thanked: 915 times | Joined on Feb 2012
#18
Originally Posted by qole View Post
Since the primary problem is that Aegis blocks the running of all unsigned binaries, and the chroot is all unsigned binaries, you would have to disable Aegis entirely. At which point, it is the same as Open Mode.
Except that it doesn't - as long as relaxed mode is turned on (it is if developer mode is on), there's nothing stopping one from running unsigned binaries. I'd suggest making the install package for HarmChOM/etc. depend on aegis-dev-mode, which should make sure this is the case. Then, the binaries inside the chroot can simply inherit the Linux capabilities obtained by the launcher through Aegis.