Re: [PATCH 0/2] file capabilities: two bugfixes

From: Casey Schaufler
Date: Fri Dec 08 2006 - 15:41:27 EST



--- "Serge E. Hallyn" <serue@xxxxxxxxxx> wrote:

> ...
> The other is that root can lose capabilities by
> executing files with
> only some capabilities set. The next two patches
> change these
> behaviors.

It was the intention of the POSIX group that
capabilities be independent of uid. I would
argue that the old bevavior was correct, that
a program marked to lose a capability ought
to even if the uid is 0.


Casey Schaufler
casey@xxxxxxxxxxxxxxxx
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/