On Tue, May 20, 2008 at 7:28 PM, Stephen Smalley [off-list ref] wrote:
On Tue, 2008-05-20 at 09:38 -0400, Stephen Smalley wrote:
quoted
Which means that he is using the dummy security module.
And it appears that a prior commit moved KEEPCAPS handling from
core prctl() to cap_task_prctl(), but didn't replicate it in
the dummy_task_prctl().
The dummy module really needs to die.
Question for the bug reporter: did you really mean to build a kernel
without capabilities support? Surprise! They don't really work when
disabled.
No; I was just trying out some random configs. This config worked till
.25 properly though.
--
Amit Shah
http://www.amitshah.net/