From 2e6d31388697ded45bcf263a98a18a625457d94a Mon Sep 17 00:00:00 2001 From: Viacheslav Hletenko Date: Thu, 27 Feb 2025 12:35:25 +0000 Subject: T7204: Container add capability MKNOD --- interface-definitions/container.xml.in | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'interface-definitions') diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in index 65ac99e12..5c320e8c6 100644 --- a/interface-definitions/container.xml.in +++ b/interface-definitions/container.xml.in @@ -31,7 +31,7 @@ Grant individual Linux capability to container instance - net-admin net-bind-service net-raw setpcap sys-admin sys-module sys-nice sys-time + net-admin net-bind-service net-raw mknod setpcap sys-admin sys-module sys-nice sys-time net-admin @@ -45,6 +45,10 @@ net-raw Permission to create raw network sockets + + mknod + Permission to create special files + setpcap Capability sets (from bounded or inherited set) @@ -66,7 +70,7 @@ Permission to set system clock - (net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-module|sys-nice|sys-time) + (net-admin|net-bind-service|net-raw|mknod|setpcap|sys-admin|sys-module|sys-nice|sys-time) -- cgit v1.2.3