Use Linux file capabilities to control privilege rather than set*id (this is orthogonal to USE=caps which uses capabilities at runtime e.g. libcap)
Package | “filecaps” Flag Description |
---|---|
app-metrics/collectd | When set collectd daemon will have set required capabilities to run most plugins even if run as unprivileged user |
net-libs/liboping | Allow non-root users to use [n]oping utility. |
sys-process/criu | Install the criu binary with file capabilities to allow for rootless CRIU |
x11-misc/i3status | Linux capabilities library is required for i3status to be able to read net bandwidth |