From 368c345ff9a648ea28ece9725522f5363b869823 Mon Sep 17 00:00:00 2001 From: Sami Kerola Date: Fri, 5 Jul 2019 20:31:05 +0100 Subject: build-sys: remove effective bit from cap_net_raw capability The iputils that use capabilities raise permissions with cap_set_flag(), so they do not need executables to have effetive bit set. Reported-by: Adrian Mouat Addresses: https://github.com/iputils/iputils/issues/194 Reference: http://man7.org/linux/man-pages/man7/capabilities.7.html Signed-off-by: Sami Kerola --- build-aux/setcap-setuid.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build-aux/setcap-setuid.sh b/build-aux/setcap-setuid.sh index f832978..01f167d 100755 --- a/build-aux/setcap-setuid.sh +++ b/build-aux/setcap-setuid.sh @@ -16,7 +16,7 @@ case "$perm_type" in # https://github.com/iputils/iputils/issues/175 ;; 'caps') - echo "$0: calling: $setcap cap_net_raw+ep $exec_path" + echo "$0: calling: $setcap cap_net_raw+p $exec_path" "$setcap" 'cap_net_raw+ep' "$exec_path" || true ;; 'setuid') -- cgit v1.2.1