فهرست منبع

Merge pull request #18951 from jfrazelle/fix-code-comment

fix code comment
Vincent Demeester 9 سال پیش
والد
کامیت
eb551baf6f
1فایلهای تغییر یافته به همراه2 افزوده شده و 1 حذف شده
  1. 2 1
      daemon/execdriver/native/seccomp_default.go

+ 2 - 1
daemon/execdriver/native/seccomp_default.go

@@ -235,7 +235,8 @@ var defaultSeccompProfile = &configs.Seccomp{
 			Args:   []*configs.Arg{},
 			Args:   []*configs.Arg{},
 		},
 		},
 		{
 		{
-			// Probably a bad idea to let containers restart
+			// Probably a bad idea to let containers restart a syscall.
+			// Possible seccomp bypass, see: https://code.google.com/p/chromium/issues/detail?id=408827.
 			Name:   "restart_syscall",
 			Name:   "restart_syscall",
 			Action: configs.Errno,
 			Action: configs.Errno,
 			Args:   []*configs.Arg{},
 			Args:   []*configs.Arg{},