1
0
Fork 0
mirror of https://github.com/moby/moby.git synced 2022-11-09 12:21:53 -05:00

Merge pull request #5528 from crosbymichael/drop-capsyslog

drop CAP_SYSLOG capability
This commit is contained in:
Michael Crosby 2014-05-01 11:52:08 -07:00
commit ab0518bfe8
4 changed files with 8 additions and 0 deletions

View file

@ -149,6 +149,7 @@ func setupCapabilities(args *execdriver.InitArgs) error {
capability.CAP_MAC_OVERRIDE, capability.CAP_MAC_OVERRIDE,
capability.CAP_MAC_ADMIN, capability.CAP_MAC_ADMIN,
capability.CAP_NET_ADMIN, capability.CAP_NET_ADMIN,
capability.CAP_SYSLOG,
} }
c, err := capability.NewPid(os.Getpid()) c, err := capability.NewPid(os.Getpid())

View file

@ -25,6 +25,7 @@ func New() *libcontainer.Container {
libcontainer.GetCapability("MAC_ADMIN"), libcontainer.GetCapability("MAC_ADMIN"),
libcontainer.GetCapability("NET_ADMIN"), libcontainer.GetCapability("NET_ADMIN"),
libcontainer.GetCapability("MKNOD"), libcontainer.GetCapability("MKNOD"),
libcontainer.GetCapability("SYSLOG"),
}, },
Namespaces: libcontainer.Namespaces{ Namespaces: libcontainer.Namespaces{
libcontainer.GetNamespace("NEWNS"), libcontainer.GetNamespace("NEWNS"),

View file

@ -91,6 +91,11 @@
"value" : 27, "value" : 27,
"key" : "MKNOD", "key" : "MKNOD",
"enabled" : true "enabled" : true
},
{
"value" : 34,
"key" : "SYSLOG",
"enabled" : false
} }
], ],
"networks" : [ "networks" : [

View file

@ -53,6 +53,7 @@ var (
{Key: "MAC_OVERRIDE", Value: capability.CAP_MAC_OVERRIDE, Enabled: false}, {Key: "MAC_OVERRIDE", Value: capability.CAP_MAC_OVERRIDE, Enabled: false},
{Key: "MAC_ADMIN", Value: capability.CAP_MAC_ADMIN, Enabled: false}, {Key: "MAC_ADMIN", Value: capability.CAP_MAC_ADMIN, Enabled: false},
{Key: "NET_ADMIN", Value: capability.CAP_NET_ADMIN, Enabled: false}, {Key: "NET_ADMIN", Value: capability.CAP_NET_ADMIN, Enabled: false},
{Key: "SYSLOG", Value: capability.CAP_SYSLOG, Enabled: false},
} }
) )