mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
8b2fcddcd2
Implements the policies for the remaining binaries called by the Docker engine and eliminates the giant whitelisted 'all files' permission in favor of granular whitelisting and child-specific policies. It should be possible now to remove the 'file' permission, but for the sake of keeping Docker unbroken, we'll try to gradually tighten the policy. Signed-off-by: Eric Windisch <eric@windisch.us> |
||
---|---|---|
.. | ||
docker-engine |