From: bugzilla-daemon@kernel.org
To: linux-man@vger.kernel.org
Subject: [Bug 216667] New: Self-contradictory description of inheritable capability set
Date: Sun, 06 Nov 2022 03:04:42 +0000 [thread overview]
Message-ID: <bug-216667-11311@https.bugzilla.kernel.org/> (raw)
https://bugzilla.kernel.org/show_bug.cgi?id=216667
Bug ID: 216667
Summary: Self-contradictory description of inheritable
capability set
Product: Documentation
Version: unspecified
Hardware: All
OS: Linux
Status: NEW
Severity: normal
Priority: P1
Component: man-pages
Assignee: documentation_man-pages@kernel-bugs.osdl.org
Reporter: robryk@gmail.com
Regression: No
man capabilities says about the inheritable capset of a process:
> This is a set of capabilities preserved across an execve(2). Inheritable
> capabilities remain inheritable when executing any program, (...)
I understand this to mean that any capability in the inheritable set will stay
inheritable across an execve (i.e. the inheritable set will not shrink across
execve).
The same manpage says in the next paragraph:
> Because inheritable capabilities are not generally preserved across execve(2)
> when running as a non-root user (...)
This seems to say the exact opposite of how I read the previous paragraph.
I am probably misunderstanding something basic here, but I am unlikely to be
the only person who does so, so I think it bears making this part clearer.
(When I try to look at the rest of the manpage to get more clarity, I fail:
- the section that describes capability transformations across execve() seems
to say that inheritable capset stays constant,
- the description of ambient capabilities implies that inheritable
capabilities differ from ambient insofar ambient ones are more "durable" across
execve().)
--
You may reply to this email to add a comment.
You are receiving this mail because:
You are watching the assignee of the bug.
next reply other threads:[~2022-11-06 3:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-11-06 3:04 bugzilla-daemon [this message]
2023-05-19 2:11 ` [Bug 216667] Self-contradictory description of inheritable capability set bugzilla-daemon
2023-05-19 2:28 ` bugzilla-daemon
2023-05-19 13:26 ` bugzilla-daemon
2023-05-19 13:26 ` bugzilla-daemon
2023-05-25 0:55 ` bugzilla-daemon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bug-216667-11311@https.bugzilla.kernel.org/ \
--to=bugzilla-daemon@kernel.org \
--cc=linux-man@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox