Files
docker-docs/daemon/execdriver
Justin Cormack 33568405f3 Block bpf syscall from default seccomp profile
The bpf syscall can load code into the kernel which may
persist beyond container lifecycle. Requires CAP_SYS_ADMIN
already.

Signed-off-by: Justin Cormack <justin.cormack@unikernel.com>
2015-12-29 17:28:30 +00:00
..
2015-12-28 19:19:26 +08:00
2015-12-28 19:19:26 +08:00
2015-11-07 08:46:36 -08:00