mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-10 02:25:56 +00:00
Explain the missing CAP_NET_RAW grant when ICMP probes are blocked
In-place updates never rewrite the systemd unit, so installs upgraded past v6.1.0-rc.1 keep a unit without AmbientCapabilities=CAP_NET_RAW and every ICMP probe fails with ping's raw stderr. Detect the capability failure and point at the unit and its fix instead (#1554).
This commit is contained in:
@@ -453,6 +453,12 @@ func probeICMP(ctx context.Context, target config.AvailabilityTarget) error {
|
||||
if details == "" {
|
||||
return fmt.Errorf("icmp probe failed: %w", err)
|
||||
}
|
||||
// Units written before v6.1.0-rc.1 lack AmbientCapabilities=CAP_NET_RAW and
|
||||
// in-place updates never rewrite the unit, so ping fails like this on every
|
||||
// upgraded install (#1554). Point at the unit instead of echoing ping stderr.
|
||||
if strings.Contains(details, "Operation not permitted") || strings.Contains(details, "cap_net_raw") {
|
||||
return fmt.Errorf("icmp probe blocked. The Pulse service unit does not grant CAP_NET_RAW, so ping cannot open a socket. Re-run the Pulse installer to regenerate the unit, or add a systemd override with AmbientCapabilities=CAP_NET_RAW and CapabilityBoundingSet=CAP_NET_RAW, then restart the service")
|
||||
}
|
||||
if len(details) > 240 {
|
||||
details = details[:240]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user