mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Merge pull request #4059 from alexlarsson/no-netadmin-caps
lxc: Drop NET_ADMIN capability in non-privileged containers
This commit is contained in:
commit
3c215ba410
1 changed files with 1 additions and 0 deletions
|
@ -120,6 +120,7 @@ func setupCapabilities(args *execdriver.InitArgs) error {
|
|||
capability.CAP_AUDIT_CONTROL,
|
||||
capability.CAP_MAC_OVERRIDE,
|
||||
capability.CAP_MAC_ADMIN,
|
||||
capability.CAP_NET_ADMIN,
|
||||
}
|
||||
|
||||
c, err := capability.NewPid(os.Getpid())
|
||||
|
|
Loading…
Add table
Reference in a new issue