summaryrefslogtreecommitdiff
path: root/interface-definitions
diff options
context:
space:
mode:
authorAnthony Rabbito <hello@anthonyrabbito.com>2023-09-03 12:15:59 -0400
committerAnthony Rabbito <hello@anthonyrabbito.com>2023-09-03 12:15:59 -0400
commite623c10ab41ee4187fc43e9a7a832b1c8c6e0527 (patch)
tree1bfb31164089b504be7b332e68a9b52ec39f4787 /interface-definitions
parent630d40046b4fd1b58060c42a075e19d870ac69ba (diff)
downloadvyos-1x-e623c10ab41ee4187fc43e9a7a832b1c8c6e0527.tar.gz
vyos-1x-e623c10ab41ee4187fc43e9a7a832b1c8c6e0527.zip
feat(T5544): Allow CAP_SYS_MODULE to be set on containers
Signed-off-by: Anthony Rabbito <hello@anthonyrabbito.com>
Diffstat (limited to 'interface-definitions')
-rw-r--r--interface-definitions/container.xml.in8
1 files changed, 6 insertions, 2 deletions
diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in
index 6b712a70f..9d8b1e057 100644
--- a/interface-definitions/container.xml.in
+++ b/interface-definitions/container.xml.in
@@ -25,7 +25,7 @@
<properties>
<help>Container capabilities/permissions</help>
<completionHelp>
- <list>net-admin net-bind-service net-raw setpcap sys-admin sys-time</list>
+ <list>net-admin net-bind-service net-raw setpcap sys-admin sys-module sys-time</list>
</completionHelp>
<valueHelp>
<format>net-admin</format>
@@ -48,11 +48,15 @@
<description>Administation operations (quotactl, mount, sethostname, setdomainame)</description>
</valueHelp>
<valueHelp>
+ <format>sys-module</format>
+ <description>Load and unload kernel modules</description>
+ </valueHelp>
+ <valueHelp>
<format>sys-time</format>
<description>Permission to set system clock</description>
</valueHelp>
<constraint>
- <regex>(net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-time)</regex>
+ <regex>(net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-module|sys-time)</regex>
</constraint>
<multi/>
</properties>