Skip to content
This repository was archived by the owner on Dec 13, 2018. It is now read-only.

AppArmor disable umount & deny proc files.#579

Closed
ewindisch wants to merge 1 commit intodocker-archive:masterfrom
ewindisch:apparmor_v1.6.2
Closed

AppArmor disable umount & deny proc files.#579
ewindisch wants to merge 1 commit intodocker-archive:masterfrom
ewindisch:apparmor_v1.6.2

Conversation

@ewindisch
Copy link
Copy Markdown
Contributor

If a container cannot mount, it cannot umount.

We should also restrict writing /proc/kcore and the
other paths libcontainer now masks.

This is a less aggressive prelude to #578.

Signed-off-by: Eric Windisch eric@windisch.us

If a container cannot mount, it cannot umount.

We should also restrict writing /proc/kcore and the
other paths libcontainer now masks.

Signed-off-by: Eric Windisch <eric@windisch.us>
@LK4D4
Copy link
Copy Markdown
Contributor

LK4D4 commented Jun 2, 2015

I personally know nothing about AppArmor.
but looks okay
LGTM
ping @crosbymichael

@ewindisch
Copy link
Copy Markdown
Contributor Author

Obsolete

@ewindisch ewindisch closed this Jul 13, 2015
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants