Re: [PATCH] add some long-missing capabilities to fs_mask

From: Valdis . Kletnieks
Date: Mon Apr 13 2009 - 17:07:16 EST


On Mon, 13 Apr 2009 09:56:14 CDT, "Serge E. Hallyn" said:
> When POSIX capabilities were introduced during the 2.1 Linux
> cycle, the fs mask, which represents the capabilities which having
> fsuid==0 is supposed to grant, did not include CAP_MKNOD and
> CAP_LINUX_IMMUTABLE. However, before capabilities the privilege
> to call these did in fact depend upon fsuid==0.

Wow. How did this manage to stay un-noticed for this long?

Attachment: pgp00000.pgp
Description: PGP signature