Component Type: kbuild config
Description: Gate setid transitions to limit CAP_SET{U/G}ID capabilities
More info: SafeSetID is an LSM module that gates the setid family of syscalls to restrict UID/GID transitions from a given UID/GID to only those approved by a system-wide whitelist. These restrictions also prohibit the given UIDs/GIDs from obtaining auxiliary privileges associated with CAP_SET{U/G}ID, such as allowing a user to set up user namespace UID mappings. If you are unsure how to answer this question, answer N.
Build project: Kconfig (Linux kconfig) (Path: security\safesetid\Kconfig )
Other views: file explorer