Argh, I edited asuming the same order of variables. Substitute
current->e{uid,gid} for one of the sides.
The intended semantics is If the user is not
* the allowed user
or
* member of the allowed group
or
* cabable of CAP_NET_ADMIN
then error out. I'm asuming
Thinking about it, maybe you should check each group, not just the
effective group. In that case, my change would be still wrong. However,
I'm not going to fix this anytime soon.
--
Funny quotes:
15. I drive way too fast to worry about cholesterol.
-