[PATCH] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Sat Sep 19 13:03:01 UTC 2026


> CAP_FS_SET is defined as exactly the capabilities an fsuid of 0
> historically granted (see CAP_FS_MASK in include/linux/capability.h),
> so dropping it when fsuid leaves 0 is correct by construction, not
> "too harsh". Replace the stale FIXME with this explanation.
> 
> Signed-off-by: Adriano Cordova <adrianox at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919130112.849932-1-adrianox@gmail.com?part=1




More information about the Linux-security-module-archive mailing list