From: Joshua Schmid Date: Mon, 14 Sep 2020 08:38:07 +0000 (+0200) Subject: cephadm: capadd and privileged are mutex X-Git-Tag: v15.2.9~122^2~44^2~4 X-Git-Url: http://git-server-git.apps.pok.os.sepia.ceph.com/?a=commitdiff_plain;h=67166de82a913e8266c8146f5c8a67d536065fc2;p=ceph.git cephadm: capadd and privileged are mutex Signed-off-by: Joshua Schmid (cherry picked from commit 76e5020b106e14284f63bd7cee81822ad6b1fbf0) --- diff --git a/src/cephadm/cephadm b/src/cephadm/cephadm index d354de8f22cb..35b5fe278c20 100755 --- a/src/cephadm/cephadm +++ b/src/cephadm/cephadm @@ -2536,9 +2536,11 @@ class CephContainer: cmd_args.extend([ '--privileged', # let OSD etc read block devs that haven't been chowned - '--group-add=disk', - ]) - if self.ptrace: + '--group-add=disk']) + if self.ptrace and not self.privileged: + # if privileged, the SYS_PTRACE cap is already added + # in addition, --cap-add and --privileged are mutually + # exclusive since podman >= 2.0 cmd_args.append('--cap-add=SYS_PTRACE') if self.init: cmd_args.append('--init')