fa229d09281d435153b4cfd138a2a62fa66d889b |
|
04-Jul-2014 |
Lennart Poettering <lennart@poettering.net> |
units: conditionalize configfs and debugfs with CAP_SYS_RAWIO
We really don't want these in containers as they provide a too lowlevel
look on the system.
Conditionalize them with CAP_SYS_RAWIO since that's required to access
/proc/kcore, /dev/kmem and similar, which feel similar in style. Also,
npsawn containers lack that capability. |