diff --git a/RTCP/Cobalt/OutputProc/etc/sudoers.d/setcap_cobalt b/RTCP/Cobalt/OutputProc/etc/sudoers.d/setcap_cobalt index df16728cb6d223498df74d22d76e50992766e2ab..eb1dc38526ca936f940bceb2a8a64a98e08298f6 100644 --- a/RTCP/Cobalt/OutputProc/etc/sudoers.d/setcap_cobalt +++ b/RTCP/Cobalt/OutputProc/etc/sudoers.d/setcap_cobalt @@ -1,5 +1,5 @@ ## Allows lofarbuild to add the listed capabilities to any single writable file for automated roll-out. ## Attempts to disallow adding another set of capabilities. ## Does not attempt to disallow adding the listed capabilities to other files, which would be trivial to bypass. -Cmnd_Alias SETCAP_COBALT = /sbin/setcap cap_net_raw\,cap_sys_nice\,cap_ipc_lock=ep *, ! /sbin/setcap cap_net_raw\,cap_sys_nice\,cap_ipc_lock=ep * * +Cmnd_Alias SETCAP_COBALT = /sbin/setcap cap_net_raw\,cap_sys_nice\,cap_sys_resource\,cap_ipc_lock=ep *, ! /sbin/setcap cap_net_raw\,cap_sys_nice\,cap_sys_resource\,cap_ipc_lock=ep * * lofarbuild ALL = (root) NOPASSWD: SETCAP_COBALT diff --git a/SubSystems/Dragnet/scripts/LOFAR-Dragnet-deploy.sh b/SubSystems/Dragnet/scripts/LOFAR-Dragnet-deploy.sh index 0f63428bd54464502b07fd110a47dac8512d91f4..e9b1e6b634ebea0e2124c89ce1cfe45d788eba9d 100755 --- a/SubSystems/Dragnet/scripts/LOFAR-Dragnet-deploy.sh +++ b/SubSystems/Dragnet/scripts/LOFAR-Dragnet-deploy.sh @@ -107,9 +107,9 @@ for host in $nodelist; do rm -- \"$lofar_versions_root/$archive\" && \ cd $lofar_versions_root && \ ( [ -z \"$envmodfilename\" ] || mv $envmodfilename /etc/modulefiles/lofar/ ) && \ - sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_ipc_lock=ep $prefix/bin/rtcp && \ - sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_ipc_lock=ep $prefix/bin/outputProc && \ - sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_ipc_lock=ep $prefix/bin/TBB_Writer && \ + sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_sys_resource,cap_ipc_lock=ep $prefix/bin/rtcp && \ + sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_sys_resource,cap_ipc_lock=ep $prefix/bin/outputProc && \ + sudo -n /sbin/setcap cap_net_raw,cap_sys_nice,cap_sys_resource,cap_ipc_lock=ep $prefix/bin/TBB_Writer && \ sync " >&2 & status_arr2[$arr2_i]=$!