Re: [PATCH] Completely honor prctl(PR_SET_KEEPCAPS, 1)

chris@scary.beasts.org
Wed, 8 May 2002 20:28:50 +0100 (BST)


On Wed, 8 May 2002, Keith Owens wrote:

> On Wed, 8 May 2002 03:40:11 -0600 (MDT),
> Dax Kelson <dax@gurulabs.com> wrote:
> >Originally when a process set*uided all capabilities bits were cleared.
> >Then sometime later (wish BK went back 3 years), the behaviour was
> >modified according to the comment "A process may, via prctl(), elect to
> >keep its capabilites when it calls setuid() and switches away from
> >uid==0. Both permitted and effective sets will be retained."
>
> FWIW, the change was in 2.2.18-pre18, between October 26 and 29, 2000.

I did the original change in 2.3.x. Since it is so important to get useful
capability functionality, someone (Chris Wing?) backported the change to
2.2.x.

I'll reply to the original e-mail shortly..

Cheers
Chris

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/