From 80e505ef0238d000e8f36ca99736b66daad999b7 Mon Sep 17 00:00:00 2001 From: theflakes Date: Fri, 5 Apr 2024 18:43:35 -0400 Subject: [PATCH 1/3] Add container cap sys-nice Adding sys-nice as a cap add for podman docker config in Vyos. --- interface-definitions/container.xml.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in index 7e1f4811aa..ce306804ae 100644 --- a/interface-definitions/container.xml.in +++ b/interface-definitions/container.xml.in @@ -56,7 +56,7 @@ Permission to set system clock - (net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-module|sys-time) + (net-admin|net-bind-service|net-raw|setpcap|sys-admin|sys-module|sys-nice|sys-time) From d8f260a5a3fd4ccf6bc6ba6a125e09fb65e0f391 Mon Sep 17 00:00:00 2001 From: theflakes Date: Fri, 5 Apr 2024 20:25:02 -0400 Subject: [PATCH 2/3] Add command completion and help entry for sys-nice. Add command completion and help entry for sys-nice. --- interface-definitions/container.xml.in | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in index ce306804ae..542f130111 100644 --- a/interface-definitions/container.xml.in +++ b/interface-definitions/container.xml.in @@ -25,7 +25,7 @@ Container capabilities/permissions - net-admin net-bind-service net-raw setpcap sys-admin sys-module sys-time + net-admin net-bind-service net-raw setpcap sys-admin sys-module sys-nice sys-time net-admin @@ -51,6 +51,10 @@ sys-module Load, unload and delete kernel modules + + sys-nice + Permissions to set process nice value + sys-time Permission to set system clock From b8fc0cb819a894abbea1beb53bcabb586365a13a Mon Sep 17 00:00:00 2001 From: theflakes Date: Tue, 9 Apr 2024 11:50:57 -0400 Subject: [PATCH 3/3] Update container.xml.in dropping Permission plural --- interface-definitions/container.xml.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/interface-definitions/container.xml.in b/interface-definitions/container.xml.in index 542f130111..9c3f9360f8 100644 --- a/interface-definitions/container.xml.in +++ b/interface-definitions/container.xml.in @@ -53,7 +53,7 @@ sys-nice - Permissions to set process nice value + Permission to set process nice value sys-time