kernel-netlink: Make CAP_NET_ADMIN capability optional
It is not required to use the kernel-net part of the plugin.
This commit is contained in:
@@ -66,10 +66,11 @@ plugin_t *kernel_netlink_plugin_create()
|
|||||||
private_kernel_netlink_plugin_t *this;
|
private_kernel_netlink_plugin_t *this;
|
||||||
|
|
||||||
if (!lib->caps->keep(lib->caps, CAP_NET_ADMIN))
|
if (!lib->caps->keep(lib->caps, CAP_NET_ADMIN))
|
||||||
{ /* required to bind/use XFRM sockets / create routing tables */
|
{ /* required to bind/use XFRM sockets / create/modify routing tables, but
|
||||||
DBG1(DBG_KNL, "kernel-netlink plugin requires CAP_NET_ADMIN "
|
* not if only the read-only parts of kernel-netlink-net are used, so
|
||||||
|
* we don't fail here */
|
||||||
|
DBG1(DBG_KNL, "kernel-netlink plugin might require CAP_NET_ADMIN "
|
||||||
"capability");
|
"capability");
|
||||||
return NULL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
INIT(this,
|
INIT(this,
|
||||||
|
|||||||
Reference in New Issue
Block a user