Browse Source

Merge "Add capabilities for privsep"

changes/29/333829/5
Zuul 3 years ago
committed by Gerrit Code Review
parent
commit
04c772a4cd
  1. 5
      neutron/privileged/__init__.py

5
neutron/privileged/__init__.py

@ -22,5 +22,8 @@ default = priv_context.PrivContext(
# TODO(gus): CAP_SYS_ADMIN is required (only?) for manipulating
# network namespaces. SYS_ADMIN is a lot of scary powers, so
# consider breaking this out into a separate minimal context.
capabilities=[caps.CAP_SYS_ADMIN, caps.CAP_NET_ADMIN],
capabilities=[caps.CAP_SYS_ADMIN,
caps.CAP_NET_ADMIN,
caps.CAP_DAC_OVERRIDE,
caps.CAP_DAC_READ_SEARCH],
)
Loading…
Cancel
Save