Files
docker-cli/components/engine/daemon/execdriver
Justin Cormack cb797e315a Block bpf syscall from default seccomp profile
The bpf syscall can load code into the kernel which may
persist beyond container lifecycle. Requires CAP_SYS_ADMIN
already.

Signed-off-by: Justin Cormack <justin.cormack@unikernel.com>
Upstream-commit: 33568405f34f363de49b1146119cc53bcb9e5f16
Component: engine
2015-12-29 17:28:30 +00:00
..
2015-12-28 19:19:26 +08:00
2015-12-28 19:19:26 +08:00
2015-11-07 08:46:36 -08:00