From efab2725ea5165732c5e98c0e083a4eec6e355e3 Mon Sep 17 00:00:00 2001 From: Kairui Song Date: Fri, 24 Sep 2021 17:43:30 +0800 Subject: [PATCH] Drop CapabilityBoundingSet from irqbalance service libcapng is issuing an error in the system log when irqbalance attempts to drop capabilities, but systemd service unit has already done dropped all capabilities. commit 43751df tried to fix this but it didn't fix it completely. CapabilityBoundingSet also need to be dropped. Fixes #182 Signed-off-by: Kairui Song --- misc/irqbalance.service | 1 - 1 file changed, 1 deletion(-) diff --git a/misc/irqbalance.service b/misc/irqbalance.service index 014798c..fcc29c2 100644 --- a/misc/irqbalance.service +++ b/misc/irqbalance.service @@ -8,7 +8,6 @@ ConditionVirtualization=!container EnvironmentFile=-/usr/lib/irqbalance/defaults.env EnvironmentFile=-/path/to/irqbalance.env ExecStart=/usr/sbin/irqbalance --foreground $IRQBALANCE_ARGS -CapabilityBoundingSet= ReadOnlyPaths=/ ReadWritePaths=/proc/irq RestrictAddressFamilies=AF_UNIX