)]}'
{
  "commit": "1209726ce942047c9fefe7cd427dc36f8e9ded53",
  "tree": "298e78052d6bdd92c78b22c86604f8c8364bc8d9",
  "parents": [
    "086f7316f0d400806d76323beefae996bb3849b1"
  ],
  "author": {
    "name": "Andrew G. Morgan",
    "email": "morgan@kernel.org",
    "time": "Fri Jul 04 09:59:59 2008 -0700"
  },
  "committer": {
    "name": "Linus Torvalds",
    "email": "torvalds@linux-foundation.org",
    "time": "Fri Jul 04 10:40:08 2008 -0700"
  },
  "message": "security: filesystem capabilities: fix CAP_SETPCAP handling\n\nThe filesystem capability support meaning for CAP_SETPCAP is less powerful\nthan the non-filesystem capability support.  As such, when filesystem\ncapabilities are configured, we should not permit CAP_SETPCAP to \u0027enhance\u0027\nthe current process through strace manipulation of a child process.\n\nSigned-off-by: Andrew G. Morgan \u003cmorgan@kernel.org\u003e\nAcked-by: Serge Hallyn \u003cserue@us.ibm.com\u003e\nCc: David Howells \u003cdhowells@redhat.com\u003e\nSigned-off-by: Andrew Morton \u003cakpm@linux-foundation.org\u003e\nSigned-off-by: Linus Torvalds \u003ctorvalds@linux-foundation.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "5edabc7542ae00c46e568456285f9bf5f369f2e6",
      "old_mode": 33188,
      "old_path": "security/commoncap.c",
      "new_id": "33d34330841344f7329e1b1f313cc531c65aa7a9",
      "new_mode": 33188,
      "new_path": "security/commoncap.c"
    }
  ]
}
