Re: [PATCH] Document how capability bits work

2012-12-09 Thread Serge Hallyn
Quoting Rob Landley (r...@landley.net): > The fact that you need multiple sets of capabilities per process > (permitted, inheritable, effective), plus MORE sets (plural) of > capabilities attached to executable files, plus the "capability > bounding set" which is presumably so selinux can mess with

Re: [PATCH] Document how capability bits work

2012-12-09 Thread Michael Kerrisk (man-pages)
Andy, On Sat, Dec 8, 2012 at 2:27 AM, Andy Lutomirski wrote: > On Fri, Dec 7, 2012 at 5:10 PM, Rob Landley wrote: >> On 12/07/2012 01:32:18 PM, Andy Lutomirski wrote: >>> >>> On Fri, Dec 7, 2012 at 11:21 AM, Serge Hallyn >>> wrote: >>> > Quoting Andy Lutomirski (l...@amacapital.net): >>> >> Sig

Re: [PATCH] Document how capability bits work

2012-12-08 Thread Rob Landley
On 12/07/2012 07:27:25 PM, Andy Lutomirski wrote: On Fri, Dec 7, 2012 at 5:10 PM, Rob Landley wrote: > On 12/07/2012 01:32:18 PM, Andy Lutomirski wrote: >> >> On Fri, Dec 7, 2012 at 11:21 AM, Serge Hallyn >> wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> Signed-off-by: Andy Lu

Re: [PATCH] Document how capability bits work

2012-12-07 Thread Andy Lutomirski
On Fri, Dec 7, 2012 at 5:10 PM, Rob Landley wrote: > On 12/07/2012 01:32:18 PM, Andy Lutomirski wrote: >> >> On Fri, Dec 7, 2012 at 11:21 AM, Serge Hallyn >> wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> Signed-off-by: Andy Lutomirski >> >> --- >> >> Documentation/security/ca

Re: [PATCH] Document how capability bits work

2012-12-07 Thread Rob Landley
On 12/07/2012 01:32:18 PM, Andy Lutomirski wrote: On Fri, Dec 7, 2012 at 11:21 AM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> Signed-off-by: Andy Lutomirski >> --- >> Documentation/security/capabilities.txt | 161 >> 1 file chang

Re: [PATCH] Document how capability bits work

2012-12-07 Thread Andy Lutomirski
On Fri, Dec 7, 2012 at 11:21 AM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> Signed-off-by: Andy Lutomirski >> --- >> Documentation/security/capabilities.txt | 161 >> >> 1 file changed, 161 insertions(+) >> create mode 100644 Docume

Re: [PATCH] Document how capability bits work

2012-12-07 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > Signed-off-by: Andy Lutomirski > --- > Documentation/security/capabilities.txt | 161 > > 1 file changed, 161 insertions(+) > create mode 100644 Documentation/security/capabilities.txt TBH, I think a pointer to t

[PATCH] Document how capability bits work

2012-12-07 Thread Andy Lutomirski
Signed-off-by: Andy Lutomirski --- Documentation/security/capabilities.txt | 161 1 file changed, 161 insertions(+) create mode 100644 Documentation/security/capabilities.txt diff --git a/Documentation/security/capabilities.txt b/Documentation/security/capabili