basic: Drop ambient inherited capabilities by default 43/277743/1
authorKevin Kuehler <keur@xcf.berkeley.edu>
Sun, 24 Nov 2019 09:27:09 +0000 (01:27 -0800)
committerŁukasz Stelmach <l.stelmach@samsung.com>
Tue, 12 Jul 2022 18:01:46 +0000 (20:01 +0200)
commitfa09a000766eb1779ab110496e40ac25ea6b9a46
tree9dcc59f5b60dd4c1534882f0ee1d7253bda7f71b
parent27b7cf01161e1688277ce959ea985bd27d16aed4
basic: Drop ambient inherited capabilities by default

Modify the functions capability_update_inherited_set() and
capability_ambient_set_apply() to drop capabilities not explicitly
requested by the user.

Change-Id: I6e5c6426b946e652bc1fd0f75a8ae41bd2b9f8e2
Origin: https://github.com/systemd/systemd/commit/82d832b435a0ae799011aeec75584af8188fb8db
Signed-off-by: Łukasz Stelmach <l.stelmach@sasmsung.com>
src/basic/capability-util.c