Jelajahi Sumber

Add AUDIT_WRITE cap

Fixes #6345

Thanks @larsks for outstanding investigation

Docker-DCO-1.1-Signed-off-by: Alexandr Morozov <lk4d4math@gmail.com> (github: LK4D4)
Alexandr Morozov 11 tahun lalu
induk
melakukan
29ecc95c31
1 mengubah file dengan 1 tambahan dan 0 penghapusan
  1. 1 0
      daemon/execdriver/native/template/default_template.go

+ 1 - 0
daemon/execdriver/native/template/default_template.go

@@ -23,6 +23,7 @@ func New() *libcontainer.Config {
 			"NET_BIND_SERVICE",
 			"NET_BIND_SERVICE",
 			"SYS_CHROOT",
 			"SYS_CHROOT",
 			"KILL",
 			"KILL",
+			"AUDIT_WRITE",
 		},
 		},
 		Namespaces: map[string]bool{
 		Namespaces: map[string]bool{
 			"NEWNS":  true,
 			"NEWNS":  true,