From 883fc4edf97ffa43561290110875d6c3111d3d76 Mon Sep 17 00:00:00 2001 From: =?utf8?q?=D0=90=D0=B7=D0=B0=D0=BB=D0=B8=D1=8F=20=D0=A1=D0=BC=D0=B0?= =?utf8?q?=D1=80=D0=B0=D0=B3=D0=B4=D0=BE=D0=B2=D0=B0?= Date: Tue, 11 Oct 2022 19:39:44 +0500 Subject: [PATCH] Remove CAP_SYS_MODULE from the capability bounding set. --- data/configs/config_base | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/configs/config_base b/data/configs/config_base index 8bcff5c..f996bb4 100644 --- a/data/configs/config_base +++ b/data/configs/config_base @@ -5,7 +5,7 @@ lxc.arch = LXCARCH lxc.autodev = 0 # lxc.autodev.tmpfs.size = 25000000 -lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot +lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner ipc_lock sys_chroot lxc.mount.auto = cgroup:ro sys:ro proc -- 2.47.3