[PATCH v2] security: commoncap: clarify CAP_FS_SET comment in cap_task_fix_setuid()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Mon Sep 21 02:55:26 UTC 2026


> CAP_FS_SET is exactly the set of capabilities that an fsuid of 0
> historically granted (see CAP_FS_MASK in include/linux/capability.h),
> so cap_task_fix_setuid() drops that set from the effective set when
> fsuid leaves 0.  Replace the stale FIXME with this explanation.
> 
> Signed-off-by: Adriano Cordova <adrianox at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921025209.1023530-1-adrianox@gmail.com?part=1




More information about the Linux-security-module-archive mailing list