Skip to content

Conversation

@Lukas1811
Copy link

With the old CapabilityBoundingSet the systemd service is not capable of loading (actually searching for) all permissions in the /etc/usbguard/rules.d folder. Adding CAP_DAC_READ_SEARCH allows the daemon running in a service to load rules from the rules folder.

See Issue #654

With the old CapabilityBoundingSet the systemd service is not capable of loading (actually searching for) all permissions in the /etc/usbguard/rules.d folder.
Adding CAP_DAC_READ_SEARCH allows the daemon running in a service to load rules from the rules folder.
@Cropi
Copy link
Member

Cropi commented Jul 14, 2025

Hello,
I am not able to reproduce it on Debian/Ubuntu. I've tried earlier versions as well. This should be a pretty basic use case, so I would expect others to report it but no one has mentioned this is not working properly.
If you could provide me a reproducer that would be great.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants