From ce785d832c88e4c0477f58eb30af9b531829712c Mon Sep 17 00:00:00 2001 From: Luis Guilherme Coelho Date: Sun, 20 Oct 2024 21:02:54 -0300 Subject: [PATCH] buer: privilege: Update network privileged programs to make use only of cap_net_raw=ep instead of setuid --- operating-systems/buer/privilege.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/operating-systems/buer/privilege.scm b/operating-systems/buer/privilege.scm index ad5497e..99203f5 100644 --- a/operating-systems/buer/privilege.scm +++ b/operating-systems/buer/privilege.scm @@ -48,7 +48,7 @@ (define network (list (privileged-program (program (file-append inetutils "/bin/ping")) - (setuid? #t)) + (capabilities "cap_net_raw=ep")) (privileged-program (program (file-append inetutils "/bin/ping6")) - (setuid? #t)))) + (capabilities "cap_net_raw=ep"))))