From: Азалия Смарагдова Date: Tue, 30 Aug 2022 16:15:13 +0000 (+0500) Subject: Container capabilities have been restricted. X-Git-Tag: 1.3.2~5 X-Git-Url: https://glassweightruler.freedombox.rocks/gitweb/waydroid.git/commitdiff_plain/2c63dbf6c2d5f97523299a4ac7657de54a9a2c72?ds=inline Container capabilities have been restricted. --- diff --git a/data/configs/config_1 b/data/configs/config_1 index 9cc28f9..cc99781 100644 --- a/data/configs/config_1 +++ b/data/configs/config_1 @@ -7,6 +7,8 @@ lxc.autodev = 0 # lxc.autodev.tmpfs.size = 25000000 lxc.aa_profile = unconfined +lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot + lxc.init_cmd = /init lxc.mount.auto = cgroup:ro sys:ro proc diff --git a/data/configs/config_2 b/data/configs/config_2 index 6a1aca0..172e1e7 100644 --- a/data/configs/config_2 +++ b/data/configs/config_2 @@ -7,6 +7,7 @@ lxc.autodev = 0 # lxc.autodev.tmpfs.size = 25000000 lxc.apparmor.profile = unconfined +lxc.cap.keep = audit_control sys_nice wake_alarm setpcap setgid setuid sys_ptrace sys_admin wake_alarm block_suspend sys_time net_admin net_raw net_bind_service kill dac_override dac_read_search fsetid mknod syslog chown sys_resource fowner sys_module ipc_lock sys_chroot lxc.no_new_privs = 1 lxc.init.cmd = /init