root改不了/etc/selinux/config,不能存盘。
/etc/sudo.conf不存在
然后sudo 和sudo -i的capabilities输出到文件后,diff结果是相同。用下面的程序获取cap。
#include <iostream>
#include <cap-ng.h>
int main() {
// 获取当前进程的capabilities
capng_get_caps_process();
// 打印capabilities
std::cout << "effective: ";
capng_print_caps_text(CAPNG_PRINT_STDOUT, CAPNG_EFFECTIVE);
printf("\n");
std::cout << "permitted: ";
capng_print_caps_text(CAPNG_PRINT_STDOUT, CAPNG_PERMITTED);
printf("\n");
std::cout << "inheritable: ";
capng_print_caps_text(CAPNG_PRINT_STDOUT, CAPNG_INHERITABLE);
printf("\n");
std::cout << "bounding set: ";
capng_print_caps_text(CAPNG_PRINT_STDOUT, CAPNG_BOUNDING_SET);
printf("\n");
/*
std::cout << "ambient: ";
capng_print_caps_text(CAPNG_PRINT_STDOUT, CAPNG_AMBIENT);
printf("\n");
*/
return 0;
}
【 在 JulyClyde 的大作中提到: 】
: 改配置文件重启一下试试
--
FROM 123.118.191.*