Allow add-ons to use CAP_BPF
and CAP_PERFMON
#4130
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Proposed change
Pending:
This allows add-ons to use
CAP_BPF
andCAP_PERFMON
as privileged capabilities.I intentionally left these two out of the math which decreases points of security if the add-on uses these features, but I'm happy to change if told to.
Type of change
Additional information
intel_gpu_top
from within add-ons errors withFailed to initialize PMU! (Permission denied)
operating-system#2314, `intel_gpu_top` from within add-ons errors with `Failed to initialize PMU! (Permission denied)` operating-system#2319Checklist
black --fast supervisor tests
)If API endpoints of add-on configuration are added/changed: