From e623c10ab41ee4187fc43e9a7a832b1c8c6e0527 Mon Sep 17 00:00:00 2001 From: Anthony Rabbito Date: Sun, 3 Sep 2023 12:15:59 -0400 Subject: feat(T5544): Allow CAP_SYS_MODULE to be set on containers Signed-off-by: Anthony Rabbito --- interface-definitions/container.xml.in | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'interface-definitions/container.xml.in') diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in index 6b712a70f..9d8b1e057 100644 --- a/interface-definitions/container.xml.in +++ b/interface-definitions/container.xml.in @@ -25,7 +25,7 @@ Container capabilities/permissions - net-admin net-bind-service net-raw setpcap sys-admin sys-time + net-admin net-bind-service net-raw setpcap sys-admin sys-module sys-time net-admin @@ -47,12 +47,16 @@ sys-admin Administation operations (quotactl, mount, sethostname, setdomainame) + + sys-module + Load and unload kernel modules + sys-time Permission to set system clock - (net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-time) + (net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-module|sys-time) -- cgit v1.2.3