mirror of
https://github.com/waydroid/waydroid.git
synced 2026-04-24 17:08:19 -04:00
Remove CAP_SYS_MODULE from the capability bounding set.
This commit is contained in:
committed by
Alessandro Astone
parent
6b89a1c822
commit
883fc4edf9
@@ -5,7 +5,7 @@ lxc.arch = LXCARCH
|
||||
lxc.autodev = 0
|
||||
# lxc.autodev.tmpfs.size = 25000000
|
||||
|
||||
lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot
|
||||
lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner ipc_lock sys_chroot
|
||||
|
||||
lxc.mount.auto = cgroup:ro sys:ro proc
|
||||
|
||||
|
||||
Reference in New Issue
Block a user