]> git.ipfire.org Git - thirdparty/systemd.git/commit
capability: keep CAP_SETPCAP while dropping bounding caps
authorLennart Poettering <lennart@poettering.net>
Wed, 6 Mar 2019 10:31:20 +0000 (11:31 +0100)
committerLennart Poettering <lennart@poettering.net>
Fri, 15 Mar 2019 14:33:09 +0000 (15:33 +0100)
commit9a2c59119c504691c01ef23af2b99409cfda4c90
treeb40201ab31e6519724a4a7a2b842151f32317334
parent75910ed9f40471d3d25684ae61d242dbc2766f5a
capability: keep CAP_SETPCAP while dropping bounding caps

The kernel only allows dropping bounding caps as long as we have
CAP_SETPCAP. Hence, let's keep that before dropping the bounding caps,
and afterwards drop them too.
src/basic/capability-util.c