Thread (42 messages) flat view 42 messages, 4 authors, 2015-02-26

Re: [PATCH] capabilities: Ambient capability set V1

From: Christoph Lameter <hidden>
Date: 2015-02-24 15:58:18
Also in: lkml

On Tue, 24 Feb 2015, Serge E. Hallyn wrote:
The other way to look at it then is that it's basically as though the
privileged task (which has CAP_SETFCAP) could've just added fI=full to
all binaries on the filesystem;  instead it's using the ambient set
so that the risk from fI=full is contained to its own process tree.
The way that our internal patch works is to leave these things alone and
just check the ambient mask in the *capable*() functions. That way the
behavior of the existing cap bits does not change but the ambient caps
stay available. Apps have no surprises.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help