From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752798AbbCGVf1 (ORCPT ); Sat, 7 Mar 2015 16:35:27 -0500 Received: from h2.hallyn.com ([78.46.35.8]:37409 "EHLO h2.hallyn.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750855AbbCGVfY (ORCPT ); Sat, 7 Mar 2015 16:35:24 -0500 Date: Sat, 7 Mar 2015 15:35:22 -0600 From: "Serge E. Hallyn" To: Christoph Lameter Cc: Andy Lutomirski , "Serge E. Hallyn" , Serge Hallyn , Jonathan Corbet , Aaron Jones , LSM List , "linux-kernel@vger.kernel.org" , Andrew Morton , "Andrew G. Morgan" , Mimi Zohar , Austin S Hemmelgarn , Markku Savela , Jarkko Sakkinen , Linux API , Michael Kerrisk Subject: Re: [PATCH] capabilities: Ambient capability set V2 Message-ID: <20150307213522.GA9833@mail.hallyn.com> References: <20150301233359.GA22196@mail.hallyn.com> <20150305171326.GA14998@mail.hallyn.com> <20150306163443.GA28386@mail.hallyn.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, Mar 07, 2015 at 09:06:46AM -0600, Christoph Lameter wrote: > On Fri, 6 Mar 2015, Andy Lutomirski wrote: > > > > christoph@fujitsu-haswell:~$ getcap ambient_test > > > > > > ambient_test = cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_nice+eip > > > > I think that's right. fI doesn't set pI. > > Ok then that is the point of pI if it cannot be set? It can be set! Anything with CAP_SETPCAP can fill it's pI. When it and its children exec(), pI' = pI.