-
Notifications
You must be signed in to change notification settings - Fork 18.9k
seccomp: whitelist quotactl with CAP_SYS_ADMIN #34445
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
ping @justincormack PTAL |
c20d047 to
9f0f9f7
Compare
|
This probably requires changes in the documentation for the next release; @pmoust could you also open a pull request for the documentation in the |
The quotactl syscall is being whitelisted in default seccomp profile, gated by CAP_SYS_ADMIN. Signed-off-by: Panagiotis Moustafellos <pmoust@elastic.co>
9f0f9f7 to
cf6e1c5
Compare
thaJeztah
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
changes LGTM though
@pmoust can you do a follow up for the documentation changes?
Updated the description of reasons why `quotactl` is blocked by the default seccomp profile. Ref: http://man7.org/linux/man-pages/man2/quotactl.2.html Rel: moby/moby#34445 Signed-off-by: Panagiotis Moustafellos <pmoust@elastic.co>
Updated the description of reasons why `quotactl` is blocked by the default seccomp profile. Ref: http://man7.org/linux/man-pages/man2/quotactl.2.html Rel: moby/moby#34445 Signed-off-by: Panagiotis Moustafellos <pmoust@elastic.co>
|
@thaJeztah Doc PR at docker/docs#4139 @justincormack I had made a typo, fixed in cf6e1c5, you might also wanna check on the followup doc PR as the description changed to better reflect the reason why |
Updated the description of reasons why `quotactl` is blocked by the default seccomp profile. Ref: http://man7.org/linux/man-pages/man2/quotactl.2.html Rel: moby/moby#34445 Signed-off-by: Panagiotis Moustafellos <pmoust@elastic.co>
The quotactl syscall is being whitelisted in default seccomp profile,
gated by CAP_SYS_ADMIN.
Signed-off-by: Panagiotis Moustafellos pmoust@elastic.co
Fixes: #34444