Files
containerd/oci
Andrew G. Morgan 6906b57c72 Fix the Inheritable capability defaults.
The Linux kernel never sets the Inheritable capability flag to
anything other than empty. Non-empty values are always exclusively
set by userspace code.

[The kernel stopped defaulting this set of capability values to the
 full set in 2000 after a privilege escalation with Capabilities
 affecting Sendmail and others.]

Signed-off-by: Andrew G. Morgan <morgan@kernel.org>
2022-02-01 13:55:46 -08:00
..
2018-02-19 10:32:26 +09:00
2021-05-25 09:17:16 +02:00
2021-08-22 09:31:50 +09:00
2022-01-04 09:27:54 +02:00
2021-08-22 09:31:50 +09:00