Inspect protected process state owned by another user.
beam.process_statusbeam.process_limitsbeam.process_memorybeam.process_tree
Grant process-inspection capabilities to the Emisar service
sudo install -d -m 0755 /etc/systemd/system/emisar.service.d sudo rm -f /etc/systemd/system/emisar.service.d/10-elixir-beam-host-access.conf printf '%s\n' '[Service]' 'AmbientCapabilities=CAP_SYS_PTRACE CAP_DAC_READ_SEARCH' | sudo tee /etc/systemd/system/emisar.service.d/20-elixir-beam-process-inspection.conf >/dev/null sudo systemctl daemon-reload sudo systemctl restart emisar
systemctl show emisar --property=AmbientCapabilities --value | grep -Fwi cap_sys_ptrace systemctl show emisar --property=AmbientCapabilities --value | grep -Fwi cap_dac_read_search
Impact: Every Emisar action on this runner can inspect, attach to, and modify processes outside the runner user, and bypass host file read and directory search permissions.