aports/testing/conntracct/dont-run-setcap.patch
2020-09-29 11:04:11 -03:00

20 lines
696 B
Diff

diff --git a/magefile.go b/magefile.go
index f995949..368c873 100644
--- a/magefile.go
+++ b/magefile.go
@@ -51,15 +51,6 @@ func Build() error {
return err
}
- // 'Minimal' capability set to run without being uid 0.
- // cap_sys_admin for calling bpf().
- // cap_ipc_lock for locking memory for the ring buffer.
- // cap_dac_override for opening /sys/kernel/debug/tracing/*
- // cap_net_admin for managing sysctl net.netfilter.nf_conntrack_acct
- if err := sh.Run("sudo", "setcap", "cap_sys_admin,cap_ipc_lock,cap_net_admin,cap_dac_override,cap_sys_resource+eip", realPath); err != nil {
- return err
- }
-
fmt.Printf("Successfully built %s!\n", buildPath)
return nil
}