Explicitly request NET_RAW privileges - #1142
Conversation
Today by default Supervisor/Docker grants NET_RAW capabilities to all apps. This might change in the future. Explicitly request NET_RAW privileges which are required by utilities like nmap, tcpdump and mtr they all are raw-socket tools.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. WalkthroughThe SSH add-on configuration now includes the ChangesSSH capability configuration
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~2 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The requested NET_RAW capability is intentionally added for SSH raw-socket utilities, with no concrete merge-blocking risk identified. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the socket gate Comment |
Proposed Changes
Today by default Supervisor/Docker grants NET_RAW capabilities to all apps. This might change in the future. Explicitly request NET_RAW privileges which are required by utilities like nmap, tcpdump and mtr they all are raw-socket tools.
Related Issues
home-assistant/supervisor#7230
Summary by CodeRabbit