)]}'
{
  "commit": "3318a386e4ca68c76e0294363d29bdc46fcad670",
  "tree": "da0da58f10bcb7dd7a885f6032b46d1025af208b",
  "parents": [
    "e06f42d6c127883e58b747048752f44ae208ae47"
  ],
  "author": {
    "name": "Serge Hallyn",
    "email": "serue@us.ibm.com",
    "time": "Thu Oct 30 11:52:23 2008 -0500"
  },
  "committer": {
    "name": "Linus Torvalds",
    "email": "torvalds@linux-foundation.org",
    "time": "Sat Nov 01 09:49:45 2008 -0700"
  },
  "message": "file caps: always start with clear bprm-\u003ecaps_*\n\nWhile Linux doesn\u0027t honor setuid on scripts.  However, it mistakenly\nbehaves differently for file capabilities.\n\nThis patch fixes that behavior by making sure that get_file_caps()\nbegins with empty bprm-\u003ecaps_*.  That way when a script is loaded,\nits bprm-\u003ecaps_* may be filled when binfmt_misc calls prepare_binprm(),\nbut they will be cleared again when binfmt_elf calls prepare_binprm()\nnext to read the interpreter\u0027s file capabilities.\n\nSigned-off-by: Serge Hallyn \u003cserue@us.ibm.com\u003e\nAcked-by: David Howells \u003cdhowells@redhat.com\u003e\nAcked-by: Andrew G. Morgan \u003cmorgan@kernel.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "399bfdb9e2da99c4ef81fdd8b0391b1f5571c371",
      "old_mode": 33188,
      "old_path": "security/commoncap.c",
      "new_id": "3976613db829044ab435ee21b7a6ad2161a6441c",
      "new_mode": 33188,
      "new_path": "security/commoncap.c"
    }
  ]
}
