]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
mountfsd: uncomment CapabilityBoundingSet= line
authorLennart Poettering <lennart@poettering.net>
Sat, 23 Aug 2025 06:08:06 +0000 (08:08 +0200)
committerZbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
Mon, 13 Oct 2025 15:54:07 +0000 (17:54 +0200)
Since mountfsd was added in 702a52f4b5d49cce11e2adbc740deb3b644e2de0 the
caps bounding set line was commented. That's an accident. Fix that. (We
need to add a bunch of caps to the list).

(cherry picked from commit 818bd1dfa1e4ac222b1fc5d238807e49fd1d7939)
(cherry picked from commit 897018cc472d4bcd6d0cd749f8fdf75b81518da4)

units/systemd-mountfsd.service.in

index 20a9b425abd272e071beef94849e85e09cdbdabe..c34e5606e2006cd6a136eaf5f02641d41dd6f931 100644 (file)
@@ -17,7 +17,7 @@ Before=sysinit.target shutdown.target
 DefaultDependencies=no
 
 [Service]
-#CapabilityBoundingSet=CAP_DAC_READ_SEARCH CAP_SYS_RESOURCE CAP_BPF CAP_PERFMON CAP_SETGID CAP_SETUID
+CapabilityBoundingSet=CAP_DAC_READ_SEARCH CAP_SYS_RESOURCE CAP_BPF CAP_PERFMON CAP_SETGID CAP_SETUID CAP_DAC_OVERRIDE CAP_CHOWN CAP_SYS_ADMIN
 ExecStart={{LIBEXECDIR}}/systemd-mountfsd
 IPAddressDeny=any
 LimitNOFILE={{HIGH_RLIMIT_NOFILE}}