Michael Crosby
|
d31ae5aed8
|
Use libcontainer cap drop method
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@docker.com> (github: crosbymichael)
|
2014-06-19 16:00:53 -04:00 |
|
Dinesh Subhraveti
|
cf331cdd6a
|
Maintain a whitelist of capabilities rather than droplist
This fixes 6/18 vulnerability
Docker-DCO-1.1-Signed-off-by: Dinesh Subhraveti <dineshs@altiscale.com> (github: dineshs-altiscale)
|
2014-06-19 03:34:04 -04:00 |
|
Michael Crosby
|
8194556337
|
Update libcontainer imports
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
|
2014-06-10 19:58:15 -07:00 |
|
Michael Crosby
|
6158ccad97
|
Move libcontainer deps into libcontainer
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
|
2014-06-09 15:52:12 -07:00 |
|
William Thurston
|
bf7f360dca
|
Fixes #5749
libcontainer support for arbitrary route table entries
Docker-DCO-1.1-Signed-off-by: William Thurston <me@williamthurston.com> (github: jhspaybar)
|
2014-05-28 17:42:02 +00:00 |
|
Michael Crosby
|
a785882b29
|
Setup host networking for lxc and native
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
|
2014-05-05 10:08:59 -07:00 |
|
Eiichi Tsukata
|
cac0cea03f
|
drop CAP_SYSLOG capability
Kernel capabilities for privileged syslog operations are currently splitted into
CAP_SYS_ADMIN and CAP_SYSLOG since the following commit:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ce6ada35bdf710d16582cc4869c26722547e6f11
This patch drops CAP_SYSLOG to prevent containers from messing with
host's syslog (e.g. `dmesg -c` clears up host's printk ring buffer).
Closes #5491
Docker-DCO-1.1-Signed-off-by: Eiichi Tsukata <devel@etsukata.com> (github: Etsukata)
Docker-DCO-1.1-Signed-off-by: Michael Crosby <michael@crosbymichael.com> (github: crosbymichael)
|
2014-05-01 11:43:55 -07:00 |
|
Alexander Larsson
|
359b7df5d2
|
Rename runtime/* to daemon/*
Docker-DCO-1.1-Signed-off-by: Alexander Larsson <alexl@redhat.com> (github: alexlarsson)
|
2014-04-17 14:43:01 -07:00 |
|