# SPDX-License-Identifier: GPL-2.0-only config [31mCONFIG_SECURITY_SAFESETID[0m bool "Gate setid transitions to limit CAP_SET{U/G}ID capabilities" depends on [31mCONFIG_SECURITY[0m select [31mCONFIG_SECURITYFS[0m default n help SafeSetID is an [31mCONFIG_LSM[0m module that gates the setid family of syscalls to restrict UID/GID transitions from a given UID/GID to only those approved by a system-wide whitelist. These restrictions also prohibit the given UIDs/GIDs from obtaining auxiliary privileges associated with CAP_SET{U/[31mCONFIG_G[0m}ID, such as allowing a user to set up user namespace UID mappings. If you are unsure how to answer this question, answer N. |