瀏覽代碼

Merge pull request #5907 from vmarmol/caps

Don't drop CAP_FOWNER in the container.
Michael Crosby 11 年之前
父節點
當前提交
a3a26cd349
共有 1 個文件被更改,包括 5 次插入4 次删除
  1. 5 4
      daemon/execdriver/native/template/default_template.go

+ 5 - 4
daemon/execdriver/native/template/default_template.go

@@ -10,12 +10,13 @@ import (
 func New() *libcontainer.Container {
 func New() *libcontainer.Container {
 	container := &libcontainer.Container{
 	container := &libcontainer.Container{
 		Capabilities: []string{
 		Capabilities: []string{
-			"MKNOD",
-			"SETUID",
-			"SETGID",
 			"CHOWN",
 			"CHOWN",
-			"NET_RAW",
 			"DAC_OVERRIDE",
 			"DAC_OVERRIDE",
+			"FOWNER",
+			"MKNOD",
+			"NET_RAW",
+			"SETGID",
+			"SETUID",
 		},
 		},
 		Namespaces: map[string]bool{
 		Namespaces: map[string]bool{
 			"NEWNS":  true,
 			"NEWNS":  true,