Bug 839998 - systemd has full capabilities
systemd has full capabilities
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: libcap-ng (Show other bugs)
All Linux
high Severity high
: beta
: ---
Assigned To: Steve Grubb
BaseOS QE Security Team
Depends On:
  Show dependency treegraph
Reported: 2012-07-13 08:11 EDT by Miroslav Vadkerti
Modified: 2013-12-23 02:35 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-07-24 14:17:20 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Miroslav Vadkerti 2012-07-13 08:11:38 EDT
Description of problem:
in RHEL6 init had these caps:

in RHEL7 systemd has these caps:

Is this a problem in systemd or are the full caps ok in systemd?

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. pscap -a | egrep "(init|systemd)"
Actual results:
Full caps

Expected results:
Systemd has expected caps only

Additional info:
Let me know if this is not a bug (i will fix the test), or reassing to systemd
Comment 1 Steve Grubb 2012-07-13 09:03:47 EDT
It think its OK for systemd to have full capabilities. The ones that should are programs that normally spawn other programs like: xinetd, crond, sshd, gdm. I think this can be closed.

Note You need to log in before you can comment on or make changes to this bug.