From patchwork Thu Feb 27 10:34:17 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Lorenzo Bianconi X-Patchwork-Id: 1245715 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=openvswitch.org (client-ip=140.211.166.136; helo=silver.osuosl.org; envelope-from=ovs-dev-bounces@openvswitch.org; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=redhat.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=ZDutiRtR; dkim-atps=neutral Received: from silver.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 48SpvH2NMVz9sP7 for ; Thu, 27 Feb 2020 21:34:35 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by silver.osuosl.org (Postfix) with ESMTP id 595882291D; Thu, 27 Feb 2020 10:34:32 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from silver.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FehK084IpvAe; Thu, 27 Feb 2020 10:34:30 +0000 (UTC) Received: from lists.linuxfoundation.org (lf-lists.osuosl.org [140.211.9.56]) by silver.osuosl.org (Postfix) with ESMTP id 14F0222128; Thu, 27 Feb 2020 10:34:30 +0000 (UTC) Received: from lf-lists.osuosl.org (localhost [127.0.0.1]) by lists.linuxfoundation.org (Postfix) with ESMTP id 01B17C08A0; Thu, 27 Feb 2020 10:34:30 +0000 (UTC) X-Original-To: dev@openvswitch.org Delivered-To: ovs-dev@lists.linuxfoundation.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by lists.linuxfoundation.org (Postfix) with ESMTP id 5AAD7C0177 for ; Thu, 27 Feb 2020 10:34:28 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 4407D87DDB for ; Thu, 27 Feb 2020 10:34:28 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7ov3RRqcCag1 for ; Thu, 27 Feb 2020 10:34:27 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from us-smtp-delivery-1.mimecast.com (us-smtp-2.mimecast.com [205.139.110.61]) by hemlock.osuosl.org (Postfix) with ESMTPS id 64E5B87D80 for ; Thu, 27 Feb 2020 10:34:27 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1582799665; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=rpOGyi96jHCwKdCw1upuI8Xwn7ahF4Zh21Im+uSx0Dk=; b=ZDutiRtRe0sAWMi7uY38NuFNgv/jJ/rUxjFLDWNs+g8fJBvQwkEXEOPGYq9cBQJyc0A/P7 RQcMC9V7aEmHTwMpO/TwkinHolYbs78tETaRwK+zqmwYunBMlLbU6CKYEGlNyvZkHYVAt1 6Itiw5mi4Wg3PGOws8xX1VCMV4a4kUE= Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-352-xsEoXCSoNpabT4UQ07L38g-1; Thu, 27 Feb 2020 05:34:24 -0500 X-MC-Unique: xsEoXCSoNpabT4UQ07L38g-1 Received: by mail-wm1-f72.google.com with SMTP id 7so544559wmf.9 for ; Thu, 27 Feb 2020 02:34:23 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=LSeFmWKxt8n/MS0P7IFc4ICdJo3SxsmWvdzcUZMOklY=; b=lghQ2BIjLVxta0x7P/oVAfp8kzxL+b0gReOUNxjXqP4NDhC2Edc2rzFSSOZNGSMDBH 1/x/xKnuel9ZZNp+pV6ueJsDpNe1pfFxwy/5PuaQ7ca+Qk8x4vcmm9RTlv9yWpMUBE+4 /1XyZ21aBIj46T5Q3fz8hR/rj7+l/uSGWFX003u38bptmOO9e/iEiLGYXFJaIMlfARxR pRdS+RKAeD0Gyy5epscPqwGdGydRWateGVPo8XPVeHS31Z8GV0vo95LXJUVcCCUelaM9 TZTYwZQA191s4+pcFnDHQuY2PDcdlxy1+jpoku5M2DB/enrJS90HuZCWvEhY2znzjbtQ YyzA== X-Gm-Message-State: APjAAAWw6w/2ZcdcKNiNSo3JOyuDLVcAEftuoO0Vr1mQHeMh1NUiib/R rneGs3odq8XltQVzOHPA0iqPchqsJSEc5cfWvTt+A6my7q2j32PqyiyvXahZu3hJtpHaU+SUqS0 LxziPleeDBfGY X-Received: by 2002:a5d:4446:: with SMTP id x6mr4052824wrr.312.1582799662644; Thu, 27 Feb 2020 02:34:22 -0800 (PST) X-Google-Smtp-Source: APXvYqxbhQGaOHlEJxy9JlNr8iqHEEM7NiiOmnOFkWIJ3esnji0FrgaEjvUPTYpq5DLFC4RiAFRyvA== X-Received: by 2002:a5d:4446:: with SMTP id x6mr4052803wrr.312.1582799662391; Thu, 27 Feb 2020 02:34:22 -0800 (PST) Received: from localhost.lan ([151.48.146.246]) by smtp.gmail.com with ESMTPSA id u62sm7285672wmu.17.2020.02.27.02.34.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Feb 2020 02:34:19 -0800 (PST) From: Lorenzo Bianconi To: dev@openvswitch.org Date: Thu, 27 Feb 2020 11:34:17 +0100 Message-Id: <700192e933993be74b4c26c3e97ceada5e75415d.1582799491.git.lorenzo.bianconi@redhat.com> X-Mailer: git-send-email 2.24.1 MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Cc: yinxu@redhat.com Subject: [ovs-dev] [PATCH ovn] controller: grant cap_net_admin to ovn-controller X-BeenThere: ovs-dev@openvswitch.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: ovs-dev-bounces@openvswitch.org Sender: "dev" ovn-controller is currently running as non-root so it is not allowed to configure system networking breaking ovn QoS support. Fix the issue granting CAP_NET_ADMIN capability to ovn-controller process Tested-by: Ying Xu Signed-off-by: Lorenzo Bianconi Acked-by: Numan Siddique --- controller/ovn-controller.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/controller/ovn-controller.c b/controller/ovn-controller.c index cacaaa578..53d80806f 100644 --- a/controller/ovn-controller.c +++ b/controller/ovn-controller.c @@ -1733,7 +1733,7 @@ main(int argc, char *argv[]) char *ovs_remote = parse_options(argc, argv); fatal_ignore_sigpipe(); - daemonize_start(false); + daemonize_start(true); char *abs_unixctl_path = get_abs_unix_ctl_path(); retval = unixctl_server_create(abs_unixctl_path, &unixctl);