commit | 160da84dbb39443fdade7151bc63a88f8e953077 | [log] [tgz] |
---|---|---|
author | Eric W. Biederman <ebiederm@xmission.com> | Tue Jul 02 10:04:54 2013 -0700 |
committer | Eric W. Biederman <ebiederm@xmission.com> | Fri Aug 30 17:30:39 2013 -0700 |
tree | ddc0f7993f773a610b888a75b2a00a2520c053f9 | |
parent | dbef0c1c4c5f8ce5d1f5bd8cee092a7afb4ac21b [diff] |
userns: Allow PR_CAPBSET_DROP in a user namespace. As the capabilites and capability bounding set are per user namespace properties it is safe to allow changing them with just CAP_SETPCAP permission in the user namespace. Acked-by: Serge Hallyn <serge.hallyn@canonical.com> Tested-by: Richard Weinberger <richard@nod.at> Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>