| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| abstractions | ||
| profiles | ||
| Makefile.am | ||
| README | ||
| container-rules | ||
| container-rules.base | ||
| lxc-containers | ||
| lxc-generate-aa-rules.py | ||
| usr.bin.lxc-start |
Prevent privileged containers from messing with the host's pci devices
directly. Refuse access under /proc/bus, and drop cap_sys_rawio. Some
containers may need to re-enable cap_sys_rawio (i.e. if they run an
X server).
It may be desirable to break some of this stuff into files which can be
separately included (or not included), but this patch isn't the right
place for that.
Signed-off-by:
Serge Hallyn <serge.hallyn@ubuntu.com>
| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| abstractions | Loading commit data... | |
| profiles | Loading commit data... | |
| Makefile.am | Loading commit data... | |
| README | Loading commit data... | |
| container-rules | Loading commit data... | |
| container-rules.base | Loading commit data... | |
| lxc-containers | Loading commit data... | |
| lxc-generate-aa-rules.py | Loading commit data... | |
| usr.bin.lxc-start | Loading commit data... |