The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Read process capability masksgrep -E '^Cap(Inh|Prm|Eff|Bnd|Amb):' /proc/1234/statusView examples
Decode a capability maskcapsh --decode=0000000000000400View examples
Show current capability contextcapsh --printView examples
Read file capabilitiesgetcap -v /usr/local/bin/ping-helperView examples
Scan one filesystem treesudo getcap -r /usr/local 2>/dev/nullView examples
Grant network bind capabilitysudo setcap 'cap_net_bind_service=ep' \ /usr/local/bin/webdView examples
Remove file capabilitiessudo setcap -r /usr/local/bin/webdView examples
Verify expected capabilitygetcap /usr/local/bin/webd | grep -F 'cap_net_bind_service=ep'View examples
Show highest supported capabilitycat /proc/sys/kernel/cap_last_capView examples
Check no-new-privilegesgrep '^NoNewPrivs:' /proc/1234/statusView examples
Inspect unit capability policysystemctl show webd.service -p CapabilityBoundingSet -p \ AmbientCapabilities -p NoNewPrivilegesView examples
Analyze unit exposuresystemd-analyze security webd.serviceView examples
List file attributeslsattr -d /etc/important.confView examples
Set immutablesudo chattr +i /etc/important.confView examples
Clear immutablesudo chattr -i /etc/important.confView examples
Set append-onlysudo chattr +a /var/log/example.logView examples
List extended attributesgetfattr --dump --absolute-names /usr/local/bin/webdView examples
Read raw capability xattrgetfattr --name=security.capability --hex \ /usr/local/bin/webdView examples
Copy while preserving xattrscp --archive --preserve=xattr /usr/local/bin/webd \ /srv/stage/webdView examples
Archive with xattrstar --xattrs --acls -cpf webd-backup.tar \ /usr/local/bin/webdView examples

Linux capabilities split root privilege into individual bits, but many remain broad enough for full host compromise. File capabilities are security.capability extended attributes whose behavior depends on exec transitions, namespaces, mount options, and kernel support. File attributes such as immutable and append-only are separate controls. Grant the smallest tested privilege, preserve xattrs in deployment and backup, and keep a rollback path before changing privileged binaries or boot-critical files.

Step by step

Detailed examples

01

Read all five capability sets in context

Permitted bounds what a thread may make effective; effective is checked by the kernel; inheritable and ambient participate in exec transitions; the bounding set limits future acquisition. Capability state is per thread even though tools often display a process. Decode against the running system because new kernels add capabilities.

Inspect one process
grep -E '^(Name|Uid|Gid|CapInh|CapPrm|CapEff|CapBnd|CapAmb|NoNewPrivs):' /proc/1234/status
capsh --decode=0000000000000400
cat /proc/sys/kernel/cap_last_cap
Back to quick reference ↑
02

Grant file capabilities only to controlled immutable artifacts

setcap writes security.capability to an executable. Replacing the file usually drops that xattr, while a writable executable lets an attacker inherit its privilege. Verify ownership, modes, hash, mount policy, interpreter behavior, and update workflow. Scripts generally do not safely gain file capabilities through their interpreter.

Review before a narrow grant
stat /usr/local/bin/webd
sha256sum /usr/local/bin/webd
findmnt -T /usr/local/bin/webd -o TARGET,SOURCE,FSTYPE,OPTIONS
getcap -v /usr/local/bin/webd
# sudo setcap 'cap_net_bind_service=ep' /usr/local/bin/webd
Back to quick reference ↑
03

Audit bounded paths and compare to an allowlist

Unexpected file capabilities are high-value persistence. Scan package and locally managed executable trees, but avoid crossing huge or remote filesystems blindly. Compare path, inode, owner, mode, package provenance, hash, and exact capabilities to a reviewed baseline; do not remove entries before establishing why they exist.

Inventory local executable capabilities
sudo getcap -r /usr/local 2>/dev/null
sudo getcap -r /opt 2>/dev/null
findmnt -R /usr/local
# Compare results to a version-controlled allowlist and package inventory.
Back to quick reference ↑
04

Interpret privilege relative to the governing user namespace

Capabilities are checked in relation to a user namespace, and namespaced file capabilities can be scoped to a root user ID. Container root does not automatically equal initial-namespace root, but broad device access, host mounts, or CAP_SYS_ADMIN can erase isolation. Capability support and decomposition vary by kernel.

Inspect namespace context
readlink /proc/1234/ns/user
readlink /proc/1/ns/user
grep -E '^Cap(Bnd|Eff|Amb):' /proc/1234/status
cat /proc/sys/kernel/cap_last_cap
Back to quick reference ↑
05

Prefer service-scoped capability policy

systemd can restrict CapabilityBoundingSet and grant AmbientCapabilities to a service while NoNewPrivileges prevents later exec-based privilege gain. Ambient capabilities must also be permitted and inheritable. Combine narrow capabilities with an unprivileged user and other sandbox controls, then test required behavior and restart rollback.

Audit one service boundary
systemctl show webd.service -p User -p Group -p CapabilityBoundingSet -p AmbientCapabilities -p NoNewPrivileges
systemd-analyze security webd.service
systemctl cat webd.service
Back to quick reference ↑
06

Use immutable and append-only flags as guardrails, not access control

chattr flags are filesystem-dependent and require privilege to change. Immutable can block writes, renames, deletion, and package upgrades; append-only can break log rotation and applications that rewrite headers. Attackers with sufficient privilege can clear them. Record every flag and an emergency reversal procedure.

Inspect flags before maintenance
findmnt -T /etc/important.conf -o FSTYPE,OPTIONS
lsattr -d /etc/important.conf /var/log/example.log
# Clear a documented guard only for the maintenance window:
# sudo chattr -i /etc/important.conf
Back to quick reference ↑
07

Distinguish capability xattrs from ACLs and security labels

security.capability is one xattr; SELinux labels, IMA/EVM metadata, user attributes, and POSIX ACLs are separate. Dumping xattrs can expose provenance or security data. Destination filesystems, copy tools, archives, network protocols, and privileges may omit or transform metadata.

Inspect metadata layers
getcap -v /usr/local/bin/webd
getfattr --dump --absolute-names /usr/local/bin/webd
getfacl --absolute-names /usr/local/bin/webd
ls -lZ /usr/local/bin/webd
Back to quick reference ↑
08

Test capability preservation across every deployment path

Copy, archive, extraction, package installation, overlay filesystems, and restore can lose file capabilities or restore them unexpectedly. A successful data checksum does not validate metadata. Test backup and rollback on the destination filesystem, inventory getcap after deployment, and avoid privileged extraction from untrusted archives.

Verify staged metadata
getcap -v /usr/local/bin/webd /srv/stage/webd
getfattr --name=security.capability --hex /usr/local/bin/webd
getfattr --name=security.capability --hex /srv/stage/webd
sha256sum /usr/local/bin/webd /srv/stage/webd
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux man-pages projectcapabilities(7) Manual Pageman7.org
  2. libcap Projectsetcap(8) Manual Pageman7.org
  3. libcap Projectgetcap(8) Manual Pageman7.org
  4. Linux man-pages projectxattr(7) Manual Pageman7.org
  5. e2fsprogs Projectchattr(1) Manual Pageman7.org
  6. systemd Projectsystemd.exec Manualfreedesktop.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback