What is Nostr?
Lennart Poettering /
npub1rk2…zenj
2024-12-11 09:17:51
in reply to nevent1q…wnha

Lennart Poettering on Nostr: The idea is that by default processes run by root have all capabilities and those run ...

The idea is that by default processes run by root have all capabilities and those run by other users have none. But if you tweak your process' capability you can also have processes owned by UID 0 that lack permissions to do various things, or have processes owned by an UID other than 0 which do have more elevated permissions, akin to root's.

Process capabilities can be controlled via the CapabilityBoundingSet= and AmbientCapabilities= knobs in systemd service files, …
Author Public Key
npub1rk2uxtv6nk262nucavh259t085a8rhzfaj3vjc9jhzvkyav0rnqqxqzenj