On Wed, 2008-10-22 at 21:13 -0700, Andrew G. Morgan wrote:
So what did you two agree on for when to collect fcaps type information?
Any time bprm->cap_post_exec_permitted is non-zero?
The syscall record (rather than this auxilary fcaps record) will
indicate that the syscall failed. it says something like success=no.