diff options
| author | Djalal Harouni <tixxdz@opendz.org> | 2016-10-07 20:38:05 +0200 | 
|---|---|---|
| committer | Djalal Harouni <tixxdz@opendz.org> | 2016-10-12 13:39:49 +0200 | 
| commit | 2cd0a735470894bd2d25147442285744764633a1 (patch) | |
| tree | ced267bfca1489c3f5334838321f8e8589c1079f /src/shared/fstab-util.c | |
| parent | 3ae33295f00be5e2836f009bf1991b0caddf80b7 (diff) | |
core:sandbox: remove CAP_SYS_RAWIO on PrivateDevices=yes
The rawio system calls were filtered, but CAP_SYS_RAWIO allows to access raw
data through /proc, ioctl and some other exotic system calls...
Diffstat (limited to 'src/shared/fstab-util.c')
0 files changed, 0 insertions, 0 deletions
