Merge "grant bpfloader CAP_CHOWN"

This commit is contained in:
Maciej Żenczykowski 2020-02-14 21:19:16 +00:00 committed by Gerrit Code Review
commit 1d896ff5e5

View File

@ -12,7 +12,7 @@ allow bpfloader devpts:chr_file { read write };
# for retrieving a pinned map when bpfloader do a run time restart.
allow bpfloader self:bpf { prog_load prog_run map_read map_write map_create };
allow bpfloader self:global_capability_class_set sys_admin;
allow bpfloader self:capability { chown sys_admin };
###
### Neverallow rules