Victor Marmol
|
92614928ce
Make libcontainer's CapabilitiesMask into a []string (Capabilities).
|
11 years ago |
Michael Crosby
|
adbe3096e8
Add cpuset cpus support for docker
|
11 years ago |
Michael Crosby
|
01fec73ba4
Update after namespace refactor
|
11 years ago |
Guillaume J. Charmes
|
70fef1460a
Merge pull request #4441 from crosbymichael/add-net-flag
|
11 years ago |
Michael Crosby
|
db5f6b4aa0
Improve libcontainer namespace and cap format
|
11 years ago |
Michael Crosby
|
a785882b29
Setup host networking for lxc and native
|
11 years ago |
Johan Euphrosine
|
a60159f3b1
runconfig: add -net container:name option
|
11 years ago |
Michael Crosby
|
f5139233b9
Update restrictions for better handling of mounts
|
11 years ago |
Jérôme Petazzoni
|
1c4202a614
Mount /proc and /sys read-only, except in privileged containers.
|
11 years ago |
Michael Crosby
|
f0e6e135a8
Initial work on selinux patch
|
11 years ago |
unclejack
|
44140f7909
Merge pull request #5411 from crosbymichael/lockdown
|
11 years ago |
Victor Marmol
|
f188b9f623
Separating cgroup Memory and MemoryReservation.
|
11 years ago |
Michael Crosby
|
5ba1242bdc
Mount over dev and only copy allowed nodes in
|
11 years ago |
Michael Crosby
|
81e5026a6a
No not mount sysfs by default for non privilged containers
|
11 years ago |
Michael Crosby
|
60a90970bc
Add restrictions to proc in libcontainer
|
11 years ago |
Guillaume J. Charmes
|
813cebc64f
Merge branch 'master' into load-profile
|
11 years ago |
Alexander Larsson
|
359b7df5d2
Rename runtime/* to daemon/*
|
11 years ago |