Commit 44931bc7 by dlezcano

Add more capabilities

From: Daniel Lezcano <daniel.lezcano@free.fr> lxc-execute and lxc-create need capability to mount. Signed-off-by: 's avatarDaniel Lezcano <dlezcano@fr.ibm.com>
parent 4c8ab83b
......@@ -71,18 +71,23 @@ rm -rf %{buildroot}
mkdir -p /var/lxc
chmod ugo+w /var/lxc
setcap cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-execute && \
setcap cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-start && \
setcap cap_sys_admin=ep %{_bindir}/lxc-init
setcap cap_sys_admin=ep %{_bindir}/lxc-netstat
setcap cap_sys_admin=ep %{_bindir}/lxc-create
setcap cap_sys_chroot,cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-execute
setcap cap_sys_chroot,cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-start
setcap cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-restart && \
%{_bindir}/lxc-restart
setcap cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
%{_bindir}/lxc-unshare && \
setcap cap_sys_admin=ep \
%{_bindir}/lxc-init && \
setcap cap_sys_admin=ep \
%{_bindir}/lxc-netstat
%{_bindir}/lxc-unshare
%files
%defattr(-,root,root)
......@@ -99,6 +104,9 @@ setcap cap_sys_admin=ep \
%changelog
* Mon Feb 16 2009 Daniel Lezcano <daniel.lezcano@free.fr> - Version 0.6.0
- Added more capabilities to the executables
* Sun Jan 25 2009 Daniel Lezcano <daniel.lezcano@free.fr> - Version 0.6.0
- Reduced spec file
......
......@@ -126,18 +126,27 @@ lxc_version_LDADD = liblxc.la
install-exec-local:
-@export PATH=$$PATH:/sbin:/usr/sbin && \
mkdir -p $(localstatedir) && \
setcap cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
\
setcap cap_sys_admin=ep $(bindir)/lxc-create && \
\
setcap cap_sys_chroot,cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
$(bindir)/lxc-execute && \
setcap cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
\
setcap cap_sys_chroot,cap_setpcap,cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
$(bindir)/lxc-start && \
\
setcap cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
$(bindir)/lxc-restart && \
\
setcap cap_net_admin,cap_net_raw,cap_sys_admin,cap_dac_override=ep \
$(bindir)/lxc-unshare && \
\
setcap cap_sys_admin=ep \
$(bindir)/lxc-init && \
\
setcap cap_sys_admin=ep \
$(bindir)/lxc-netstat && \
\
mkdir -p $(prefix)/var/lxc && \
chmod ugo+rw $(prefix)/var/lxc || \
(echo && echo && \
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment