Michael Crosby
|
db5f6b4aa0
Improve libcontainer namespace and cap format
|
11 lat temu |
Michael Crosby
|
f5139233b9
Update restrictions for better handling of mounts
|
11 lat temu |
Jérôme Petazzoni
|
1c4202a614
Mount /proc and /sys read-only, except in privileged containers.
|
11 lat temu |
Michael Crosby
|
f0e6e135a8
Initial work on selinux patch
|
11 lat temu |
unclejack
|
44140f7909
Merge pull request #5411 from crosbymichael/lockdown
|
11 lat temu |
Victor Marmol
|
f188b9f623
Separating cgroup Memory and MemoryReservation.
|
11 lat temu |
Michael Crosby
|
5ba1242bdc
Mount over dev and only copy allowed nodes in
|
11 lat temu |
Michael Crosby
|
81e5026a6a
No not mount sysfs by default for non privilged containers
|
11 lat temu |
Michael Crosby
|
60a90970bc
Add restrictions to proc in libcontainer
|
11 lat temu |
Guillaume J. Charmes
|
813cebc64f
Merge branch 'master' into load-profile
|
11 lat temu |
Alexander Larsson
|
359b7df5d2
Rename runtime/* to daemon/*
|
11 lat temu |