Kaynağa Gözat

fix code comment

Signed-off-by: Jessica Frazelle <acidburn@docker.com>
Jessica Frazelle 9 yıl önce
ebeveyn
işleme
b4c14a0bb8

+ 2 - 1
daemon/execdriver/native/seccomp_default.go

@@ -235,7 +235,8 @@ var defaultSeccompProfile = &configs.Seccomp{
 			Args:   []*configs.Arg{},
 			Args:   []*configs.Arg{},
 		},
 		},
 		{
 		{
-			// Probably a bad idea to let containers restart
+			// Probably a bad idea to let containers restart a syscall.
+			// Possible seccomp bypass, see: https://code.google.com/p/chromium/issues/detail?id=408827.
 			Name:   "restart_syscall",
 			Name:   "restart_syscall",
 			Action: configs.Errno,
 			Action: configs.Errno,
 			Args:   []*configs.Arg{},
 			Args:   []*configs.Arg{},