Lines Matching full:capable
4 # capable Trace security capabilitiy checks (cap_capable()).
7 # USAGE: capable [-h] [-v] [-p PID] [-K] [-U]
25 ./capable # trace capability checks
26 ./capable -v # verbose: include non-audit checks
27 ./capable -p 181 # only trace PID 181
28 ./capable -K # add kernel stacks to trace
29 ./capable -U # add user-space stacks to trace
30 ./capable -x # extra fields: show TID and INSETID columns
31 ./capable --unique # don't repeat stacks for the same pid or cgroup
32 ./capable --cgroupmap mappath # only trace cgroups in this BPF map
33 ./capable --mntnsmap mappath # only trace mount namespaces in the map