mirror of
				https://github.com/moby/moby.git
				synced 2022-11-09 12:21:53 -05:00 
			
		
		
		
	Merge pull request #4059 from alexlarsson/no-netadmin-caps
lxc: Drop NET_ADMIN capability in non-privileged containers
This commit is contained in:
		
						commit
						3c215ba410
					
				
					 1 changed files with 1 additions and 0 deletions
				
			
		| 
						 | 
				
			
			@ -120,6 +120,7 @@ func setupCapabilities(args *execdriver.InitArgs) error {
 | 
			
		|||
		capability.CAP_AUDIT_CONTROL,
 | 
			
		||||
		capability.CAP_MAC_OVERRIDE,
 | 
			
		||||
		capability.CAP_MAC_ADMIN,
 | 
			
		||||
		capability.CAP_NET_ADMIN,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	c, err := capability.NewPid(os.Getpid())
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue