[Unit] | |
Description=Test for CapabilityBoundingSet | |
[Service] | |
ExecStart=/bin/sh -x -c 'c=$$(capsh --print | grep "Bounding set "); test "$$c" = "Bounding set =cap_chown,cap_fowner,cap_kill"' | |
Type=oneshot | |
CapabilityBoundingSet=CAP_FOWNER | |
CapabilityBoundingSet=CAP_KILL CAP_CHOWN |