[arch-general] Linux Kernel capabilities

Jens Adam jra at byte.cx
Fri Jul 17 11:08:53 UTC 2015


> > Unfortunately, it doesn't work and needed modules are not loaded
> > from container but only from host. I realized there is no #define
> > CAP_SYS_MODULE
> > in /usr/lib/modules/4.1.2-2-ARCH/build/include/linux/capability.h.

Look at /usr/include/linux/capability.h (linux-api-headers) instead.

> It was moved to include/uapi/linux/capability.h recentlyish.

Not really, more like December 2012, with kernel 3.7.

> As for your actual issue, SYS_CAP_MODULE isn't listed in the valid
> capabilities for --capability in the systemd-nspawn manpage. Are you
> perhaps confusing options?

Looking at the manpage it doesn't say "valid", it's just a list of
default capabilities.


--byte
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 455 bytes
Desc: Digitale Signatur von OpenPGP
URL: <https://lists.archlinux.org/pipermail/arch-general/attachments/20150717/f7f1abcd/attachment.asc>


More information about the arch-general mailing list