]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
units: conditionalize audit multicast socket on CAP_AUDIT_READ
authorLennart Poettering <lennart@poettering.net>
Wed, 20 May 2015 15:40:05 +0000 (17:40 +0200)
committerLennart Poettering <lennart@poettering.net>
Wed, 20 May 2015 15:40:05 +0000 (17:40 +0200)
The multicast logic can only work if the capability is available, hence
require it.

units/systemd-journald-audit.socket

index 35397aaeb89a387f0560eca42a5e7307f62322c8..541f2cf38d374b16a232fd88b039ad9401924f90 100644 (file)
@@ -11,6 +11,7 @@ Documentation=man:systemd-journald.service(8) man:journald.conf(5)
 DefaultDependencies=no
 Before=sockets.target
 ConditionSecurity=audit
+ConditionCapability=CAP_AUDIT_READ
 
 [Socket]
 Service=systemd-journald.service