Skip to content
Snippets Groups Projects
Unverified Commit d1857c18 authored by Thomas Woerner's avatar Thomas Woerner Committed by GitHub
Browse files

Merge pull request #1352 from freeipa/fix_sssd_on_test_container

test container: Add DAC_READ_SEARCH capability
parents edbdd3af 2d3da2d7
Branches
Tags
No related merge requests found
...@@ -4,13 +4,18 @@ ...@@ -4,13 +4,18 @@
SCRIPTDIR="$(dirname -- "$(readlink -f "${BASH_SOURCE[0]}")")" SCRIPTDIR="$(dirname -- "$(readlink -f "${BASH_SOURCE[0]}")")"
TOPDIR="$(readlink -f "${SCRIPTDIR}/../..")" TOPDIR="$(readlink -f "${SCRIPTDIR}/../..")"
. "${SCRIPTDIR}/shdefaults"
# shellcheck disable=SC1091
. "${TOPDIR}/utils/shfun" . "${TOPDIR}/utils/shfun"
container_create() { container_create() {
local name=${1} local name=${1}
local image=${2} local image=${2}
shift 2 shift 2
declare -a extra_opts=() declare -a extra_opts
readarray -t extra_opts < \
<(sed -e "s/-/--cap-drop=/g" -e "s/+/--cap-add=/g" <<< "${CAP_DEFAULTS[@]}")
for opt in "$@" for opt in "$@"
do do
[ -z "${opt}" ] && continue [ -z "${opt}" ] && continue
......
#!/bin/bash -eu
# This file is meant to be source'd by other scripts
# Set default capabilities options for freeipa containers.
# Use +CAP to add the capability and -CAP to drop the capability.
CAP_DEFAULTS=(
"+DAC_READ_SEARCH" # Required for SSSD
)
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment