Re: [PATCH] Completely honor prctl(PR_SET_KEEPCAPS, 1)

From: chris@scary.beasts.org
Date: Wed May 08 2002 - 14:28:50 EST


On Wed, 8 May 2002, Keith Owens wrote:

> On Wed, 8 May 2002 03:40:11 -0600 (MDT),
> Dax Kelson <dax@gurulabs.com> wrote:
> >Originally when a process set*uided all capabilities bits were cleared.
> >Then sometime later (wish BK went back 3 years), the behaviour was
> >modified according to the comment "A process may, via prctl(), elect to
> >keep its capabilites when it calls setuid() and switches away from
> >uid==0. Both permitted and effective sets will be retained."
>
> FWIW, the change was in 2.2.18-pre18, between October 26 and 29, 2000.

I did the original change in 2.3.x. Since it is so important to get useful
capability functionality, someone (Chris Wing?) backported the change to
2.2.x.

I'll reply to the original e-mail shortly..

Cheers
Chris

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Tue May 14 2002 - 12:00:09 EST