Skip to content
Commit 160da84d authored by Eric W. Biederman's avatar Eric W. Biederman
Browse files

userns: Allow PR_CAPBSET_DROP in a user namespace.



As the capabilites and capability bounding set are per user namespace
properties it is safe to allow changing them with just CAP_SETPCAP
permission in the user namespace.

Acked-by: default avatarSerge Hallyn <serge.hallyn@canonical.com>
Tested-by: default avatarRichard Weinberger <richard@nod.at>
Signed-off-by: default avatar"Eric W. Biederman" <ebiederm@xmission.com>
parent dbef0c1c
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment