1
0
Fork 0
mirror of https://github.com/moby/moby.git synced 2022-11-09 12:21:53 -05:00
moby--moby/contrib
Akihiro Suda 5bd4233d7b
rootless: harden slirp4netns with mount namespace and seccomp
When slirp4netns v0.4.0+ is used, now slirp4netns is hardened using
mount namespace ("sandbox") and seccomp to mitigate potential
vulnerabilities.

bump up rootlesskit: 2fcff6ceae...791ac8cb20

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
(cherry picked from commit e20b7323fb)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2019-10-05 10:54:26 +02:00
..
apparmor
desktop-integration
docker-device-tool Remove solaris build tag and `contrib/mkimage/solaris 2017-11-02 00:01:46 +00:00
gitdm Update gitdm domain-map 2017-04-10 14:28:27 -07:00
httpserver
init
mkimage mkimage: Fix Debian security presence check 2018-12-05 19:35:17 +01:00
nnp-test
syntax
syscall-test Revert "Block obsolete socket families in the default seccomp profile" 2017-05-09 14:26:00 +01:00
udev
vagrant-docker
check-config.sh Add CONFIG_IP_VS_PROTO_TCP, CONFIG_IP_VS_PROTO_UDP, IP_NF_TARGET_REDIRECT to check-config.sh 2018-11-15 11:11:48 +01:00
docker-machine-install-bundle.sh Remove 'docker-' prefix for containerd and runc binaries 2018-09-24 21:49:03 +00:00
dockerd-rootless.sh rootless: harden slirp4netns with mount namespace and seccomp 2019-10-05 10:54:26 +02:00
dockerize-disk.sh
download-frozen-image-v1.sh
download-frozen-image-v2.sh Fix error handling when go command is missing 2018-11-04 23:34:03 -05:00
editorconfig
mac-install-bundle.sh Add a script to install a bundle into Docker for Mac 2016-10-05 13:21:18 +02:00
mkimage-alpine.sh
mkimage-arch-pacman.conf mkimage-arch: provide and use own pacman.conf 2014-01-21 14:22:56 +01:00
mkimage-arch.sh
mkimage-archarm-pacman.conf
mkimage-crux.sh
mkimage-pld.sh
mkimage-yum.sh
mkimage.sh
nuke-graph-directory.sh
README.md
report-issue.sh
REVIEWERS Remove subdirectories MAINTAINERS files 2015-03-06 18:21:51 -08:00

The contrib directory contains scripts, images, and other helpful things which are not part of the core docker distribution. Please note that they could be out of date, since they do not receive the same attention as the rest of the repository.