浏览代码

Add /proc/scsi to masked paths

This is writeable, and can be used to remove devices. Containers do
not need to know about scsi devices.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
Justin Cormack 7 年之前
父节点
当前提交
a21ecdf3c8
共有 1 个文件被更改,包括 1 次插入0 次删除
  1. 1 0
      oci/defaults.go

+ 1 - 0
oci/defaults.go

@@ -119,6 +119,7 @@ func DefaultLinuxSpec() specs.Spec {
 			"/proc/timer_list",
 			"/proc/timer_stats",
 			"/proc/sched_debug",
+			"/proc/scsi",
 		},
 		ReadonlyPaths: []string{
 			"/proc/asound",