Browse Source

Merge pull request #5865 from crosbymichael/add-all-caps

Add the rest of the caps so that they are retained in privilged mode
Michael Crosby 11 years ago
parent
commit
265de539ff
1 changed files with 17 additions and 0 deletions
  1. 17 0
      pkg/libcontainer/types.go

+ 17 - 0
pkg/libcontainer/types.go

@@ -61,6 +61,23 @@ var (
 		{Key: "NET_RAW", Value: capability.CAP_NET_RAW},
 		{Key: "DAC_OVERRIDE", Value: capability.CAP_DAC_OVERRIDE},
 		{Key: "FOWNER", Value: capability.CAP_FOWNER},
+		{Key: "DAC_READ_SEARCH", Value: capability.CAP_DAC_READ_SEARCH},
+		{Key: "FSETID", Value: capability.CAP_FSETID},
+		{Key: "KILL", Value: capability.CAP_KILL},
+		{Key: "SETGID", Value: capability.CAP_SETGID},
+		{Key: "SETUID", Value: capability.CAP_SETUID},
+		{Key: "LINUX_IMMUTABLE", Value: capability.CAP_LINUX_IMMUTABLE},
+		{Key: "NET_BIND_SERVICE", Value: capability.CAP_NET_BIND_SERVICE},
+		{Key: "NET_BROADCAST", Value: capability.CAP_NET_BROADCAST},
+		{Key: "IPC_LOCK", Value: capability.CAP_IPC_LOCK},
+		{Key: "IPC_OWNER", Value: capability.CAP_IPC_OWNER},
+		{Key: "SYS_CHROOT", Value: capability.CAP_SYS_CHROOT},
+		{Key: "SYS_PTRACE", Value: capability.CAP_SYS_PTRACE},
+		{Key: "SYS_BOOT", Value: capability.CAP_SYS_BOOT},
+		{Key: "LEASE", Value: capability.CAP_LEASE},
+		{Key: "SETFCAP", Value: capability.CAP_SETFCAP},
+		{Key: "WAKE_ALARM", Value: capability.CAP_WAKE_ALARM},
+		{Key: "BLOCK_SUSPEND", Value: capability.CAP_BLOCK_SUSPEND},
 	}
 )