From b5ef66101a7b1126b67fa58c68fb3ef246327276 Mon Sep 17 00:00:00 2001 From: Anita Zhang Date: Thu, 16 Jul 2020 11:36:28 -0700 Subject: [PATCH] analyze: CAP_RAWIO -> CAP_SYS_RAWIO Fixes #16489 --- src/analyze/analyze-security.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/analyze/analyze-security.c b/src/analyze/analyze-security.c index 441fb0075c..d4996c3c65 100644 --- a/src/analyze/analyze-security.c +++ b/src/analyze/analyze-security.c @@ -914,7 +914,7 @@ static const struct security_assessor security_assessor_table[] = { .parameter = (UINT64_C(1) << CAP_NET_ADMIN), }, { - .id = "CapabilityBoundingSet=~CAP_RAWIO", + .id = "CapabilityBoundingSet=~CAP_SYS_RAWIO", .description_good = "Service has no raw I/O access", .description_bad = "Service has raw I/O access", .url = "https://www.freedesktop.org/software/systemd/man/systemd.exec.html#CapabilityBoundingSet=", -- 2.25.1