diff options
author | Jay Faulkner <jay@jvf.cc> | 2015-02-20 21:59:47 +0000 |
---|---|---|
committer | Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> | 2015-03-04 23:18:09 -0500 |
commit | 9a71b1122c6e49dd9227f82b2f53837c7ea13019 (patch) | |
tree | 3de7a9645978aed8ba18312f2c5490a0231165c2 /rules | |
parent | 9e4ded3064e9a683e004ff8f6a8ce53ac20b79d7 (diff) |
nspawn: Map all seccomp filters to capabilities
This change makes it so all seccomp filters are mapped
to the appropriate capability and are only added if that
capability was not requested when running the container.
This unbreaks the remaining use cases broken by the
addition of seccomp filters without respecting requested
capabilities.
Co-Authored-By: Clif Houck <me@clifhouck.com>
[zj: - adapt to our coding style, make struct anonymous]
Diffstat (limited to 'rules')
0 files changed, 0 insertions, 0 deletions