From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S966135AbbBCPRn (ORCPT ); Tue, 3 Feb 2015 10:17:43 -0500 Received: from resqmta-ch2-02v.sys.comcast.net ([69.252.207.34]:57663 "EHLO resqmta-ch2-02v.sys.comcast.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S965775AbbBCPRj (ORCPT ); Tue, 3 Feb 2015 10:17:39 -0500 Date: Tue, 3 Feb 2015 09:17:38 -0600 (CST) From: Christoph Lameter X-X-Sender: cl@gentwo.org To: Andy Lutomirski cc: Serge Hallyn , Casey Schaufler , Serge Hallyn , Jonathan Corbet , Aaron Jones , "Ted Ts'o" , LSM List , "linux-kernel@vger.kernel.org" , Andrew Morton Subject: Re: [capabilities] Allow normal inheritance for a configurable set of capabilities In-Reply-To: Message-ID: References: <54CFB9B8.8020701@schaufler-ca.com> <20150202180806.GE24351@ubuntumail> Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 2 Feb 2015, Andy Lutomirski wrote: > None of this could address the problem here, though: if I hold a > capability and I want to pass that capability to an exec'd helper, I > shouldn't need the fs's help to do this. Amen!