Quoting Jan Engelhardt (jengelh@computergmbh.de):I'm aware. You mean the read/write split? Nope, but it's related, and as I pointed out below it fits in pretty nicely. And he will still be able to *run* the suid binary, but if cap_bound is reduced he won't be able to use capabilities taken out of the bounding set, multiadm loaded or not. -serge -
