If a container has a bind mount from a host nfs or fuse filesystem, and does 'umount -f', it will disconnect the host's filesystem. This patch adds a seccomp rule to block umount -f from a container. It also adds that rule to the default seccomp profile. Thanks stgraber for the idea :) Signed-off-by:Serge Hallyn <serge.hallyn@ubuntu.com> Acked-by:
Stéphane Graber <stgraber@ubuntu.com>
| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| apparmor | Loading commit data... | |
| bash | Loading commit data... | |
| etc | Loading commit data... | |
| init | Loading commit data... | |
| selinux | Loading commit data... | |
| sysconfig | Loading commit data... | |
| templates | Loading commit data... | |
| yum | Loading commit data... | |
| Makefile.am | Loading commit data... | |
| acinclude.m4 | Loading commit data... | |
| tls.m4 | Loading commit data... |