Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751631AbbESUWZ (ORCPT ); Tue, 19 May 2015 16:22:25 -0400 Received: from mail-wi0-f172.google.com ([209.85.212.172]:36584 "EHLO mail-wi0-f172.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751117AbbESUWW (ORCPT ); Tue, 19 May 2015 16:22:22 -0400 Message-ID: <555B9B79.9080806@gmail.com> Date: Tue, 19 May 2015 20:22:17 +0000 From: Aaron Jones User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.6.0 MIME-Version: 1.0 To: Andy Lutomirski , Christoph Lameter CC: Jarkko Sakkinen , "Ted Ts'o" , "Andrew G. Morgan" , Andrew Morton , Serge Hallyn , Michael Kerrisk , Mimi Zohar , Linux API , Austin S Hemmelgarn , linux-security-module , LKML , Serge Hallyn , Markku Savela , Kees Cook , Jonathan Corbet Subject: Re: [PATCH v2 1/2] capabilities: Ambient capabilities References: In-Reply-To: X-Enigmail-Version: : 1.8.2 OpenPGP: id=91AFDD06224DD60AA2677ECF6E854C0FAAD4CEA4 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 865 Lines: 23 On 19/05/15 20:07, Andy Lutomirski wrote:> It's in the cover letter, rather vaguely. I think I want to change > the setpriv syntax a bit before sending it upstream, though -- it's > sucks that you have to duplicate the option. > > Perhaps the ambient-caps option should implicitly raise inheritable > caps if they're not already raised. Or maybe the absence of an > inh-caps rule should cause any requested ambient caps to be made > inheritable as well. > > --Andy I propose an additional --ambient-inh option to copy everything from --inh-caps to the ambient set. Explicit is better than implicit. -- Aaron Jones -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/