systemd: require CAP_AUDIT_WRITE for NetworkManager service
authorBeniamino Galvani <bgalvani@redhat.com>
Fri, 24 Jul 2015 15:08:30 +0000 (17:08 +0200)
committerBeniamino Galvani <bgalvani@redhat.com>
Tue, 4 Aug 2015 07:32:12 +0000 (09:32 +0200)
We need it to write messages to kernel auditing log.

data/NetworkManager.service.in

index 42b43e3..fbaf77d 100644 (file)
@@ -11,7 +11,7 @@ ExecStart=@sbindir@/NetworkManager --no-daemon
 Restart=on-failure
 # NM doesn't want systemd to kill its children for it
 KillMode=process
-CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE
 ProtectSystem=true
 ProtectHome=read-only