commit | d236de16af38ede7e6d02dbc953814378bc0d9bd | [log] [tgz] |
---|---|---|
author | Tom Cherry <tomcherry@google.com> | Wed Feb 06 10:45:56 2019 -0800 |
committer | Tom Cherry <tomcherry@google.com> | Wed Feb 06 11:25:18 2019 -0800 |
tree | f073749d06e463cb207dcd138ba78c5452bffcf4 | |
parent | 18aab0dbdc45fb147514a7b027f39ce195077a3c [diff] |
init: allow services to have no capabilities set In particular, this allows services running as the root user to have capabilities removed instead of always having full capabilities. Test: boot device with a root service with an empty capabilities option in init showing no capabilities in /proc/<pid>/status Change-Id: I569a5573ed4bc5fab0eb37ce9224ab708e980451