commit | f682d47fc474d05fd78260faeb7863d4ded5153f | [log] [tgz] |
---|---|---|
author | Dylan Reid <dgreid@chromium.org> | Thu Sep 17 21:39:07 2015 -0700 |
committer | Dylan Reid <dgreid@google.com> | Fri Oct 16 16:46:29 2015 -0700 |
tree | 32b893a32f42c550e2f8c2e1e914f1e4ad7e0879 | |
parent | b7901001ad665559de7e04e33d807715de727ddb [diff] |
minijail: Read the last valid cap value earlier. The maximum valid capability of the kernel is read from /proc. However since the ability to change mount namespaces and pivot root were added, /proc might not be available when running drop_caps. To allow capabilities to be dropped even if entering a new mount namespace, cache the last valid cap earlier and pass it to drop_caps. Change-Id: I7adc017f0cdaa242d9348495815bbb4e70a74463 Signed-off-by: Dylan Reid <dgreid@chromium.org>