Add the "CAP_FOWNER" capability to "CapabilityBoundingSet" in the sample systemd service, so that Borg can open source files without changing file access times (#1334).

This commit is contained in:
Dan Helfman
2026-07-13 16:08:52 -07:00
parent eae3341b01
commit b41f4cfa0d
2 changed files with 3 additions and 1 deletions
+1 -1
View File
@@ -60,7 +60,7 @@ ProtectSystem=full
# includes, for instance, programs to snapshot filesystems (e.g. ZFS, LVM, and
# Btrfs). But rather than commenting this out entirely, one workaround may be to
# add "CAP_SYS_ADMIN".
CapabilityBoundingSet=CAP_DAC_READ_SEARCH CAP_NET_RAW
CapabilityBoundingSet=CAP_DAC_READ_SEARCH CAP_FOWNER CAP_NET_RAW
# Lower CPU and I/O priority.
Nice=19