From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Serge E. Hallyn" Subject: Re: [PATCH] capabilities: Ambient capability set V2 Date: Sat, 7 Mar 2015 15:35:22 -0600 Message-ID: <20150307213522.GA9833@mail.hallyn.com> References: <20150301233359.GA22196@mail.hallyn.com> <20150305171326.GA14998@mail.hallyn.com> <20150306163443.GA28386@mail.hallyn.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Content-Disposition: inline In-Reply-To: Sender: linux-security-module-owner@vger.kernel.org To: Christoph Lameter Cc: Andy Lutomirski , "Serge E. Hallyn" , Serge Hallyn , Jonathan Corbet , Aaron Jones , LSM List , "linux-kernel@vger.kernel.org" , Andrew Morton , "Andrew G. Morgan" , Mimi Zohar , Austin S Hemmelgarn , Markku Savela , Jarkko Sakkinen , Linux API , Michael Kerrisk List-Id: linux-api@vger.kernel.org On Sat, Mar 07, 2015 at 09:06:46AM -0600, Christoph Lameter wrote: > On Fri, 6 Mar 2015, Andy Lutomirski wrote: > > > > christoph@fujitsu-haswell:~$ getcap ambient_test > > > > > > ambient_test = cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_nice+eip > > > > I think that's right. fI doesn't set pI. > > Ok then that is the point of pI if it cannot be set? It can be set! Anything with CAP_SETPCAP can fill it's pI. When it and its children exec(), pI' = pI.