]> glassweightruler.freedombox.rocks Git - waydroid.git/blobdiff - data/configs/config_2
Container capabilities have been restricted.
[waydroid.git] / data / configs / config_2
index 67cade1b8a07cc25d0777de79720bdc3ec961555..172e1e7bfc11f2df6c1d6d54c213a7d845b77042 100644 (file)
@@ -7,6 +7,9 @@ lxc.autodev = 0
 # lxc.autodev.tmpfs.size = 25000000
 lxc.apparmor.profile = unconfined
 
+lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot
+lxc.no_new_privs = 1
+
 lxc.init.cmd = /init
 
 lxc.mount.auto = cgroup:ro sys:ro proc