capng_lock(3) centos man page | unix.com

Man Page: capng_lock

Operating Environment: centos

Section: 3

CAPNG_LOCK(3)							   Libcap-ng API						     CAPNG_LOCK(3)

NAME
capng_lock - lock the current process capabilities settings
SYNOPSIS
#include <cap-ng.h> int capng_lock(void);
DESCRIPTION
capng_lock will take steps to prevent children of the current process to regain full privileges if the uid is 0. This should be called while possessing the CAP_SETPCAP capability in the kernel. This function will do the following if permitted by the kernel: Set the NOROOT option on for PR_SET_SECUREBITS, set the NOROOT_LOCKED option to on for PR_SET_SECUREBITS, set the PR_NO_SETUID_FIXUP option on for PR_SET_SECUREBITS, and set the PR_NO_SETUID_FIXUP_LOCKED option on for PR_SET_SECUREBITS.
RETURN VALUE
This returns 0 on success and a negative number on failure. -1 means a failure setting any of the PR_SET_SECUREBITS options.
SEE ALSO
capng_apply(3), prctl(2), capabilities(7)
AUTHOR
Steve Grubb Red Hat June 2009 CAPNG_LOCK(3)
Related Man Pages
capng_change_id(3) - debian
capng_change_id(3) - centos
captest(8) - freebsd
captest(8) - v7
captest(8) - minix
Similar Topics in the Unix Linux Community
Set hard block limit for user using quota
Best performance UNIX just for HOST Virtualization?
DB2 convert digits to binary format
Tar Command
Unsure why access time on a directory change isn't changing