The kernel never sets the inheritable capabilities for a process, they are only set by userspace. Emulate the same behavior. Closes: CVE-2022-27651 Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> |
||
|---|---|---|
| .. | ||
| run.go | ||
| run_test.go | ||
| seccomp.go | ||
| seccomp_unsupported.go | ||
| selinux.go | ||
| selinux_unsupported.go | ||
| unsupported.go | ||