diff --git a/validate/validate.go b/validate/validate.go index 53a6fc4f8..6e8c3a4a1 100644 --- a/validate/validate.go +++ b/validate/validate.go @@ -39,20 +39,44 @@ var ( "RLIMIT_RTTIME", } defaultCaps = []string{ + "CAP_AUDIT_CONTROL", + "CAP_AUDIT_READ", + "CAP_AUDIT_WRITE", + "CAP_BLOCK_SUSPEND", "CAP_CHOWN", "CAP_DAC_OVERRIDE", - "CAP_FSETID", + "CAP_DAC_READ_SEARCH", "CAP_FOWNER", + "CAP_FSETID", + "CAP_IPC_LOCK", + "CAP_IPC_OWNER", + "CAP_KILL", + "CAP_LEASE", + "CAP_LINUX_IMMUTABLE", + "CAP_MAC_ADMIN", + "CAP_MAC_OVERRIDE", "CAP_MKNOD", + "CAP_NET_ADMIN", + "CAP_NET_BIND_SERVICE", + "CAP_NET_BROADCAST", "CAP_NET_RAW", "CAP_SETGID", "CAP_SETUID", "CAP_SETFCAP", "CAP_SETPCAP", - "CAP_NET_BIND_SERVICE", + "CAP_SYS_ADMIN", + "CAP_SYS_BOOT", "CAP_SYS_CHROOT", - "CAP_KILL", - "CAP_AUDIT_WRITE", + "CAP_SYS_MODULE", + "CAP_SYS_NICE", + "CAP_SYS_PACCT", + "CAP_SYS_PTRACE", + "CAP_SYS_RAWIO", + "CAP_SYS_RESOURCE", + "CAP_SYS_TIME", + "CAP_SYS_TTY_CONFIG", + "CAP_SYSLOG", + "CAP_WAKE_ALARM", } )