Bladeren bron

Don't drop CAP_FOWNER in the container. Also sorts the list of allowed
capabilities.

Docker-DCO-1.1-Signed-off-by: Victor Marmol <vmarmol@google.com> (github: vmarmol)

Victor Marmol 11 jaren geleden
bovenliggende
commit
0abad3ae22
1 gewijzigde bestanden met toevoegingen van 5 en 4 verwijderingen
  1. 5 4
      daemon/execdriver/native/template/default_template.go

+ 5 - 4
daemon/execdriver/native/template/default_template.go

@@ -10,12 +10,13 @@ import (
 func New() *libcontainer.Container {
 	container := &libcontainer.Container{
 		Capabilities: []string{
-			"MKNOD",
-			"SETUID",
-			"SETGID",
 			"CHOWN",
-			"NET_RAW",
 			"DAC_OVERRIDE",
+			"FOWNER",
+			"MKNOD",
+			"NET_RAW",
+			"SETGID",
+			"SETUID",
 		},
 		Namespaces: map[string]bool{
 			"NEWNS":  true,