Introduce a capability shell wrapper; capsh.

Capsh is a simple 'bash' wrapper program that can be used to
raise and lower both the bset and pI capabilities before invoking
/bin/bash (hardcoded right now).

The --print option can be used as a quick test whether various
capability manipulations work as expected (or not).

Signed-off-by: Andrew G. Morgan <>
3 files changed