Skip to content

Conversation

Lukas1811
Copy link

With the old CapabilityBoundingSet the systemd service is not capable of loading (actually searching for) all permissions in the /etc/usbguard/rules.d folder. Adding CAP_DAC_READ_SEARCH allows the daemon running in a service to load rules from the rules folder.

See Issue #654

With the old CapabilityBoundingSet the systemd service is not capable of loading (actually searching for) all permissions in the /etc/usbguard/rules.d folder.
Adding CAP_DAC_READ_SEARCH allows the daemon running in a service to load rules from the rules folder.
@Cropi
Copy link
Member

Cropi commented Jul 14, 2025

Hello,
I am not able to reproduce it on Debian/Ubuntu. I've tried earlier versions as well. This should be a pretty basic use case, so I would expect others to report it but no one has mentioned this is not working properly.
If you could provide me a reproducer that would be great.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants