Package: xchpst
Version: 0.8.5-1
Severity: normal
Tags: upstream
Hi,
xchpst(8) says:
[...]
--caps-bs-keep capability[,capability...]
Keeps only the listed capabilities in the bounding set.
--caps-bs-drop capability[,capability...]
Drops the listed capabilities from the bounding set. Use only
one of the two options governing the bounding set.
--caps-keep capability[,capability...]
Retain the listed capabilities when dropping to a non-root
user.
--caps-drop capability[,capability...]
Drop the listed capabilities when dropping to a non-root user,
but retain all others.
[...]
While xhcpst --help says:
xchpst-0.8.5-1 (c) Copyright 2024,2025 Andrew Bower <[email protected]>
[...]
--cap-bs-keep CAP[,...] restrict capabilities bounding set
--cap-bs-drop CAP[,...] drop from capabilities bounding set
--caps-keep CAP[,...] keep (only) these capabilities
--caps-drop CAP[,...] drop these capabilities
[...]
(Note --cap-bs-* vs. --caps-bs-*.)
What the program actually accepts matches the output of --help, not the manpage.
Please fix the manpage rather than modifying the program to match it, to avoid
breaking existing scripts.
Thanks!
AndrĂ¡s
-- System Information:
Debian Release: forky/sid
APT prefers stable-security
APT policy: (500, 'stable-security'), (350, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Init: runit (via /run/runit.stopit)
-- no debconf information
--
If you want to know about paranoids, follow them around.