It will break libcap. And I'm not sure of the right way to address it.
So I was hoping to hear some ideas from Andrew Morgan, Chris Wright, and
Kaigai.
We can introduce new capget64() and capset64() calls, and have
capget() return -EINVAL or -EAGAIN if a high bit would be needed to
accurately get the task's capabilities.
Or we can require a new libcap, since capget and capset aren't
required for most day-to-day function anyway.
I guess now that I've written this out, it seems pretty clear
that capget64() and capget64() are the way to go. Any objections?
thanks,
-serge
-