Thread (25 messages) 25 messages, 9 authors, 2019-09-05

Re: [PATCH v2 bpf-next 2/3] bpf: implement CAP_BPF

From: Alexei Starovoitov <hidden>
Date: 2019-09-04 15:22:10
Also in: bpf, netdev

On 9/4/19 8:16 AM, Daniel Borkmann wrote:
opening/creating BPF maps" error="Unable to create map 
/run/cilium/bpffs/tc/globals/cilium_lxc: operation not permitted" 
subsys=daemon
2019-09-04T14:11:47.28178666Z level=fatal msg="Error while creating 
daemon" error="Unable to create map 
/run/cilium/bpffs/tc/globals/cilium_lxc: operation not permitted" 
subsys=daemon
Ok. We have to include caps in both cap_sys_admin and cap_bpf then.
And /same/ deployment with reverted patches, hence no CAP_BPF gets it up 
and running again:

# kubectl get pods --all-namespaces -o wide
Can you share what this magic commands do underneath?

What user do they pick to start under? and what caps are granted?
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help