Thread (21 messages) flat view 21 messages, 4 authors, 2015-03-14

Re: [PATCH] capabilities: Ambient capability set V2

From: "Serge E. Hallyn" <serge@hallyn.com>
Date: 2015-03-09 14:37:00
Also in: lkml

On Mon, Mar 09, 2015 at 07:05:24AM -0500, Christoph Lameter wrote:
On Sat, 7 Mar 2015, Serge E. Hallyn wrote:
quoted
quoted
The ancestor here is ambient_test and when it is run pI will not be set
despite the cap setting.
ambient_test is supposed to set it.
I thought the setcap +i would do it.

So the setcap and setting of the file inheritance bits has no effect on
pI? When the process starts pI is off despite fI being set?
Correct, pI must be set through capset().  Again, x in fI is saying
that the certain trusted users may have x in pP when they run the
binary;  x in pi means that the users may have x in pP when they run
certain files.  Other users running the file won't have x in pP, and
the special user running other files won't have x in pP.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help