Blame SOURCES/0005-ibft-cap-sys-admin-rh1371201.patch

52f25a
From 53a95f9ebd941c9fd2464f69ee420c4c82842eda Mon Sep 17 00:00:00 2001
52f25a
From: Thomas Haller <thaller@redhat.com>
52f25a
Date: Fri, 2 Sep 2016 15:58:42 +0200
52f25a
Subject: [PATCH] service: give CAP_SYS_ADMIN for ibft/iscsiadm (rh#1371201)
52f25a
52f25a
systemd on rhel-7.3 has a bug with merging CapabilityBoundingSet.
52f25a
https://github.com/systemd/systemd/issues/1221
52f25a
Thus it is all in one line.
52f25a
---
52f25a
 data/NetworkManager.service.in | 6 +++---
52f25a
 1 file changed, 3 insertions(+), 3 deletions(-)
52f25a
52f25a
diff --git a/data/NetworkManager.service.in b/data/NetworkManager.service.in
52f25a
index 2692935..d354b7c 100644
52f25a
--- a/data/NetworkManager.service.in
52f25a
+++ b/data/NetworkManager.service.in
52f25a
@@ -14,10 +14,10 @@ ExecStart=@sbindir@/NetworkManager --no-daemon
52f25a
 Restart=on-failure
52f25a
 # NM doesn't want systemd to kill its children for it
52f25a
 KillMode=process
52f25a
-CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT
52f25a
+#CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT
52f25a
 
52f25a
-# ibft settings plugin calls iscsiadm which needs CAP_SYS_ADMIN
52f25a
-#CapabilityBoundingSet=CAP_SYS_ADMIN
52f25a
+# ibft settings plugin calls iscsiadm which needs CAP_SYS_ADMIN (rh#1371201)
52f25a
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE CAP_NET_RAW CAP_NET_BIND_SERVICE CAP_SETGID CAP_SETUID CAP_SYS_MODULE CAP_AUDIT_WRITE CAP_KILL CAP_SYS_CHROOT CAP_SYS_ADMIN
52f25a
 
52f25a
 ProtectSystem=true
52f25a
 ProtectHome=read-only
52f25a
-- 
52f25a
2.17.1
52f25a