commit | 1d896ff5e50a89419657579d393b5d72e4a39edc | [log] [tgz] |
---|---|---|
author | Maciej Żenczykowski <maze@google.com> | Fri Feb 14 21:19:16 2020 +0000 |
committer | Gerrit Code Review <noreply-gerritcodereview@google.com> | Fri Feb 14 21:19:16 2020 +0000 |
tree | 91f93ec9211e5fca84e1fc964519d969248e2398 | |
parent | b4d3c575b3e862d45b7ad11a3abd5a8a2c0bd40c [diff] | |
parent | 1189fac418d0deee1444533e2687894b9399bb2a [diff] |
Merge "grant bpfloader CAP_CHOWN"
diff --git a/private/bpfloader.te b/private/bpfloader.te index 34921e6..8271add 100644 --- a/private/bpfloader.te +++ b/private/bpfloader.te
@@ -12,7 +12,7 @@ # for retrieving a pinned map when bpfloader do a run time restart. allow bpfloader self:bpf { prog_load prog_run map_read map_write map_create }; -allow bpfloader self:global_capability_class_set sys_admin; +allow bpfloader self:capability { chown sys_admin }; ### ### Neverallow rules