Lei
b278b668e9
Add ulimit to docker build.
...
Signed-off-by: Lei Jitang <leijitang@huawei.com >
Upstream-commit: 877dbbbde8aaf6583a81d9946e4c83db8e356b1a
Component: engine
2015-07-23 10:26:06 +08:00
Jessie Frazelle
76ec388f40
Merge pull request #14864 from ewindisch/apparmor-engine-policy
...
Add AppArmor policy for the docker binary
Upstream-commit: a7d84503128720612022d46f5c9c04602cb19f05
Component: engine
2015-07-22 13:56:33 -07:00
Jessica Frazelle
6e935ab7ff
actually update deb dockerfiles
...
Signed-off-by: Jessica Frazelle <princess@docker.com >
Upstream-commit: 1fff0a5cc5503ed2af0fd0b9bf775ebd41917a44
Component: engine
2015-07-22 13:06:04 -07:00
Eric Windisch
ae18180fac
Add AppArmor policy for the engine
...
Wraps the engine itself with an AppArmor policy.
This restricts what may be done by applications
we call out to, such as 'xz'.
Significantly, this policy also restricts the policies
to which a container may be spawned into. By default,
users will be able to transition to an unconfined
policy or any policy prefaced with 'docker-'.
Local operators may add new local policies prefaced
with 'docker-' without needing to modify this policy.
Operators choosing to disable privileged containers
will need to modify this policy to remove access
to change_policy to unconfined.
Signed-off-by: Eric Windisch <eric@windisch.us >
Upstream-commit: 39dae54a3f40035b1b7e5ca86c53d05dec832ed2
Component: engine
2015-07-22 14:20:50 -04:00
Jessie Frazelle
417958d0e1
Merge pull request #14770 from albers/completion-log-opt
...
Bash completion for log drivers and their options
Upstream-commit: 052b23e2901131393737829b03a7e8a37e9232f6
Component: engine
2015-07-21 19:58:12 -07:00
Jessie Frazelle
797e2bf06e
Merge pull request #14677 from vincentbernat/fix/zsh-completion-update-4
...
zsh: update zsh completion for docker command
Upstream-commit: 162ae444afd9a82af4c3448654bef03fedb11d04
Component: engine
2015-07-21 19:56:03 -07:00
Alexander Morozov
84681c30e3
Merge pull request #14609 from ewindisch/apparmor-policy
...
Move AppArmor policy to contrib & deb packaging
Upstream-commit: 380959dd68cd56e60a2ea93cd7f26c8d88135483
Component: engine
2015-07-21 08:48:02 -07:00
Eric Windisch
74cf202b4f
Move AppArmor policy to contrib & deb packaging
...
The automatic installation of AppArmor policies prevents the
management of custom, site-specific apparmor policies for the
default container profile. Furthermore, this change will allow
a future policy for the engine itself to be written without demanding
the engine be able to arbitrarily create and manage AppArmor policies.
- Add deb package suggests for apparmor.
- Ubuntu postinst use aa-status & fix policy path
- Add the policies to the debian packages.
- Add apparmor tests for writing proc files
Additional restrictions against modifying files in proc
are enforced by AppArmor. Ensure that AppArmor is preventing
access to these files, not simply Docker's configuration of proc.
- Remove /proc/k?mem from AA policy
The path to mem and kmem are in /dev, not /proc
and cannot be restricted successfully through AppArmor.
The device cgroup will need to be sufficient here.
- Load contrib/apparmor during integration tests
Note that this is somewhat dirty because we
cannot restore the host to its original configuration.
However, it should be noted that prior to this patch
series, the Docker daemon itself was loading apparmor
policy from within the tests, so this is no dirtier or
uglier than the status-quo.
Signed-off-by: Eric Windisch <eric@windisch.us >
Upstream-commit: 80d99236c1ef9d389dbaca73c1a949da16b56b42
Component: engine
2015-07-21 11:05:53 -04:00
Harald Albers
0bc52bd67f
Second level completions for --log-opt
...
Advanced completion for some log driver options:
gelf-address, syslog-address, syslog-facility.
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: d5aeb3398b6438ea5a1b3de4ec1e5f35d441f462
Component: engine
2015-07-21 08:25:14 +02:00
Sebastiaan van Stijn
9acb0cc0fc
Remove reference to CENTOS6 from generate script
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
Upstream-commit: 18ca5d7c0e8582bf4e31a8ca1f5c6a5dbc58d55b
Component: engine
2015-07-21 01:21:33 +02:00
Harald Albers
d43954849c
Completion: Add support for '=' in arguments to __docker_pos_first_nonflag
...
This solves several problems that arise from the special treatment of
"=" in Bash.
The fix was required as some log drivers have options in a key=value
form. It also addresses the --option=value and the negated boolean syntax
(--boolean=false).
Note that this is not a general fix for these problems, it is limited to
the __docker_pos_first_nonflag function.
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: 38acec94c49e6730ae6bdef86b85f529c1dddda6
Component: engine
2015-07-20 21:22:56 +02:00
Harald Albers
62e6e49ea2
Driver-specific completions for --log-opt
...
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: faa8b658e7e7a0e827cf7e05f64dcd2e843452ac
Component: engine
2015-07-20 20:24:01 +02:00
Harald Albers
b663092054
Add missing log drivers to bash completion
...
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: e09d0febe644f440e95a7a87e6fdfae8104743d6
Component: engine
2015-07-20 20:13:59 +02:00
Vincent Bernat
0be39dfb3a
zsh: update zsh completion for docker command
...
zsh completion is updated with the content of
felixr/docker-zsh-completion.
- felixr/docker-zsh-completion@a93e1cb7bd Fix completion of repositories with tags
- felixr/docker-zsh-completion@590ea70596 Respect provided `--host` flag when invoking docker
- felixr/docker-zsh-completion@6c557babaa Several cosmetic improvements
- felixr/docker-zsh-completion@5b63cc591a Update completion for `inspect`
- felixr/docker-zsh-completion@b7d8f2f7cc Order completions alphabetically
- felixr/docker-zsh-completion@63f6a06224 Factor completion for `build`, `create` and `run`
- felixr/docker-zsh-completion@ade49ee47f Enforce positional arguments being last
- felixr/docker-zsh-completion@850b6b6d95 Update completion for build/commit/export/exec/history/import
- felixr/docker-zsh-completion@01bfd8c075 Remove completion for `insert` and duplicate of `import`
- felixr/docker-zsh-completion@c64a1d730a Update completion for `stats` to add `--no-stream` flag
- felixr/docker-zsh-completion@5e81d78b52 Update completion for `log` to add `--since` flag
- felixr/docker-zsh-completion@b3c146a1a2 Update completion for `run` to add `--group-add` flag
- felixr/docker-zsh-completion@8d4f196ad8 Don't trigger expensive completion function for flags
- felixr/docker-zsh-completion@bd5aaa124d Add completion for `--help` everywhere
- felixr/docker-zsh-completion@3a67a0e8c4 Return appropriate status code on completion
- felixr/docker-zsh-completion@4dfcb450ea Add Steve as a regular contributor.
- felixr/docker-zsh-completion@996a1c6def Add completion for top-level flags
- felixr/docker-zsh-completion@b6df75905f Ensure short/long option are not allowed twice
- felixr/docker-zsh-completion@75b6a500a0 Complete repositories with tags only on repository match
- felixr/docker-zsh-completion@5e6292135f Factorize completion of images/repositories/tags
- felixr/docker-zsh-completion@1c504eb677 Handle repositories with ":"
- felixr/docker-zsh-completion@0a05bf818b Update completion for `pause' and `unpause'
- felixr/docker-zsh-completion@b3a63253e2 Containers name can include Swarm host
In summary:
- Swarm support
- Handling repositories with ":"
- Rework how completion of images/repositories/tags work:
- felixr/docker-zsh-completion@5e6292135f
- felixr/docker-zsh-completion@75b6a500a0
- felixr/docker-zsh-completion@a93e1cb7bd
The remaining changes are here to sync changes done in Docker repository
(mostly from PR #14074 and #14555 , by @sdurrheimer). With some minor changes:
- boolean flags don't complete their arguments (true/false)
- reuse of `--host` argument is done with `$opt_arg` to avoid parsing
error
- build/create/run common options are factorized out
- `--help` flag is handled differently
- `pause` and `unpause` accepts several containers as far as I know, so
the change is reverted
- some more, but difficult to notice (more completion for some flags I think)
Some labels are reverted, mostly because I did the merge by copy/pasting
new options instead of modifying existing options.
This commit is partial. The way the `--help` option is handled triggered
a major change due to the way things are quoted. Those changes were
partially and programmaticaly reverted in this commit only to minimize
the changes to review. The next commit will restore the full changes.
Signed-off-by: Vincent Bernat <vincent@bernat.im >
Upstream-commit: 3a1596f0f5e004f59b0d140b728ca255206ef68f
Component: engine
2015-07-20 14:25:48 +02:00
Jessica Frazelle
30e998cb02
remove centos6 from rpm builder
...
Signed-off-by: Jessica Frazelle <princess@docker.com >
Upstream-commit: af5fb9b7d0722783d6ffcc9d36e36e158d1b84b0
Component: engine
2015-07-19 14:30:48 -07:00
Jessica Frazelle
13b2b9e4b5
add tianon's suites.sh file
...
Signed-off-by: Jessica Frazelle <princess@docker.com >
Upstream-commit: 4a5fd6c0f9014456e70a369c5b31e3edb3b8d5a1
Component: engine
2015-07-15 12:48:49 -07:00
Jessie Frazelle
b069af9e3e
Merge pull request #14555 from sdurrheimer/master
...
Zsh completion updates and improvements
Upstream-commit: 386f11a63dec0f918e5d118bb5835ddde56a7b41
Component: engine
2015-07-15 10:40:41 -07:00
Jessie Frazelle
4fb7b8e2f2
Merge pull request #14608 from vincentbernat/fix/zsh-reviewers
...
zsh: remove Vincent Bernat from reviewers for ZSH completion
Upstream-commit: cf09e435c843516af8bbe0460cd5e1f014c0e01a
Component: engine
2015-07-14 07:08:06 -07:00
Steve Durrheimer
e313011735
Several cosmetic improvements in zsh completion
...
Signed-off-by: Steve Durrheimer <s.durrheimer@gmail.com >
Upstream-commit: 91a2d9cc7d4ed47d4f255ad3d6da8295483e6a89
Component: engine
2015-07-14 11:34:33 +02:00
Steve Durrheimer
05b319b1cb
Zsh completion update for the following commits:
...
- Add fluentd logging driver to zsh completion #12876
- Add inspect --type flag to zsh completion #13187
- Respect -H option in zsh completion #13195
- Fix number of argument limit for pause and unpause in zsh completion
Signed-off-by: Steve Durrheimer <s.durrheimer@gmail.com >
Upstream-commit: 12f67141f932db15fa9178b3304c7efbd485fd69
Component: engine
2015-07-14 11:32:26 +02:00
Vincent Bernat
3c6e2ebd6f
zsh: remove Vincent Bernat from reviewers for ZSH completion
...
Signed-off-by: Vincent Bernat <vincent@bernat.im >
Upstream-commit: 5dbb217bcb8eb33c4c152f7ba1b5f7fec0b579dd
Component: engine
2015-07-13 23:15:16 +02:00
Mrunal Patel
8a8cd3160c
Adds documentation for additional groups.
...
Signed-off-by: Mrunal Patel <mrunalp@gmail.com >
Upstream-commit: d77d0268eb1f419509ceb6670ff7aaa298314218
Component: engine
2015-07-13 14:47:28 -04:00
Jessie Frazelle
8014aa30a4
Merge pull request #14426 from albers/completion-events
...
Add some missing events to bash completion
Upstream-commit: 0badebe7348af1b56bce002bb8d1fca03dbdb872
Component: engine
2015-07-13 10:05:36 -07:00
Avi Miller
68020cd75e
Change generate.sh so that the yum command for packages remains generic across distros.
...
Signed-off-by: Avi Miller <avi.miller@oracle.com >
Upstream-commit: f18c4f23cc98ba4fd4fb3241571ce31062eda717
Component: engine
2015-07-10 07:34:47 +10:00
Avi Miller
414a101271
Add support for building docker-engine RPM on Oracle Linux 7.
...
Signed-off-by: Avi Miller <avi.miller@oracle.com >
Upstream-commit: 0117330ae7da7dc77d27c551fb298d842afc3890
Component: engine
2015-07-08 16:12:19 +10:00
Jessie Frazelle
9147778cbe
Merge pull request #14369 from maximkulkin/14123-dockerize-disk-with-non-en-locale
...
Fix dockerize-disk.sh working in non-en locale
Upstream-commit: 16f8afb4519ff9dbbb2ed386d0d00d3da54997b9
Component: engine
2015-07-07 17:51:29 -07:00
Harald Albers
527b90ee8b
Add some missing events to bash completion
...
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: ea26b3878421fd39e40ec264e604e9efa114592d
Component: engine
2015-07-07 09:04:15 +02:00
Jessica Frazelle
863d4d7ae6
fix rpms
...
Signed-off-by: Jessica Frazelle <princess@docker.com >
Upstream-commit: 76a853de6eee072e4874a64e4c5ffcceacdccbf1
Component: engine
2015-07-06 14:14:26 -07:00
Maxim Kulkin
44f2447bf7
Fix dockerize-disk.sh working in non-en locale
...
One part of script relies on messages that are
output by some system tool. In non-en locale
those messages get localized which breaks the
script.
This patch enforces en locale for that system
tool.
Signed-off-by: Maxim Kulkin <maxim.kulkin@gmail.com >
Upstream-commit: 8630ad1530f85c57a96f998e7251ee27c9cf267c
Component: engine
2015-07-02 16:08:12 -07:00
Shishir Mahajan
8aaef3e5b3
Flag Addition: --type flag added for docker inspect command
...
Signed-off-by: Shishir Mahajan <shishir.mahajan@redhat.com >
Upstream-commit: 2cb74e691538351efbdee7a78be6535f22c5d024
Component: engine
2015-07-01 12:14:01 -04:00
Steve Durrheimer
c59f116283
Update the zsh completion
...
Signed-off-by: Steve Durrheimer <s.durrheimer@gmail.com >
Upstream-commit: b2cc6f1b478f05c21ecd0c52ac6435480e53f472
Component: engine
2015-06-21 17:33:07 +02:00
Jessie Frazelle
6b78ff756b
Merge pull request #13935 from asbjornenge/tm_syntax_updates
...
TM syntax updates
Upstream-commit: 748814a97a0bade1375ffa9cee6009a823b6d75e
Component: engine
2015-06-15 16:12:22 -07:00
Michael Crosby
8b238203a5
Merge pull request #13942 from calavera/fix_unshare_mount_regression
...
Fix regression bind mounting shared.
Upstream-commit: 3f11e05db2c2efdac0455b693efdacc6fce1ab62
Component: engine
2015-06-15 11:25:35 -07:00
David Calavera
974ab12463
Revert "contrib/init: unshare mount namespace for inits"
...
This reverts commit b6569b6b82df4c5e29ee8f5ebd9db7e36919cefd.
Signed-off-by: David Calavera <david.calavera@gmail.com >
Upstream-commit: d8592eaff8bddb6f29c48cc39dec70db884eda00
Component: engine
2015-06-15 10:35:17 -07:00
Asbjørn Enge
77a149d3fd
Various cleanups added to asbjornenge/Docker.tmbundle (by the TM maintainer) and support for the LABEL instruction
...
Docker-DCO-1.1-Signed-off-by: Asbjorn Enge <asbjorn@hanafjedle.net > (github: asbjornenge)
Upstream-commit: dfec4a48c7ac3ea4604b0a6d400109aa2004bad9
Component: engine
2015-06-15 00:04:05 +02:00
Asbjørn Enge
c9ef6a3684
Updated TextMate install instruction - this bundle is not included in TM 😄 :rocket
...
Docker-DCO-1.1-Signed-off-by: Asbjorn Enge <asbjorn@hanafjedle.net > (github: asbjornenge)
Upstream-commit: ac8cbf4952cf745207dbd966109348bbb80c9ebd
Component: engine
2015-06-15 00:02:10 +02:00
Mary Anthony
57eb64c9c0
Carry of PR #13520
...
Removinig files
Signed-off-by: Mary Anthony <mary@docker.com >
Upstream-commit: cd44018856be421497a35d96f88dd0eec42fae43
Component: engine
2015-06-13 09:27:30 -07:00
Mary Anthony
84b8fc6fe1
Moving man pages out of docs
...
Adding in other areas per comments
Updating with comments; equalizing generating man page info
Updating with duglin's comments
Doug is right here again;fixing.
Signed-off-by: Mary Anthony <mary@docker.com >
Upstream-commit: eacae64bd89ccc95a6db7bda76d36014e71e70ac
Component: engine
2015-06-10 13:43:35 -07:00
Tianon Gravi
ecd78c774c
Merge pull request #13546 from hqhq/hq_checkconfig_rescount
...
Don't check RESOURCE_COUNTERS in new kernel
Upstream-commit: 969cb545ae5022dc38113f741f2ba3f873cfb967
Component: engine
2015-06-08 14:43:17 -07:00
Eric-Olivier Lamey
2c15e96c15
Fix docs URL in systemd service file.
...
Fixes #13799 .
Signed-off-by: Eric-Olivier Lamey <eo@lamey.me >
Upstream-commit: dbf5e36fd6257ed237f76a65ccbae4124a4f0bdf
Component: engine
2015-06-08 10:21:43 +00:00
Qiang Huang
32bfc6a4bf
Don't check RESOURCE_COUNTERS in new kernel
...
Closes : #13543
Signed-off-by: Qiang Huang <h.huangqiang@huawei.com >
Upstream-commit: 8bfc8102be4a9f0d3da936f5b80f2fb4477a558a
Component: engine
2015-06-03 17:26:39 +08:00
Jessie Frazelle
b68a27ad2e
Merge pull request #13601 from tianon/precise
...
Finally add precise/12.04 as a build-deb target
Upstream-commit: d96ca04f249e19c2d259052371a026ae4d48a3a1
Component: engine
2015-05-29 14:35:07 -07:00
Jessie Frazelle
7112e31245
Merge pull request #13604 from tianon/vim-embedded-shell
...
Add embedded shell script highlight to vim syntax
Upstream-commit: 4d9191e15d457adaa9f7721828ee06cd6eb51b1d
Component: engine
2015-05-29 14:17:07 -07:00
Tianon Gravi
4b65abde07
Adjust vim ftdetect to match "Dockerfile", "dockerfile", and "Dockerfile.*" which are all reasonably safe to assume "this is a Dockerfile"
...
Signed-off-by: Andrew "Tianon" Page <admwiggin@gmail.com >
Upstream-commit: e02744404d34027d1b358986bedd8557805aae58
Component: engine
2015-05-29 13:46:51 -07:00
Tianon Gravi
b8a51baa80
Add embedded shell script highlight to vim syntax
...
This highlights `RUN`, `CMD`, and `ENTRYPOINT` lines using shell highlighting. It doesn't bother detecting the JSON forms, but that's OK because JSON arrays highlight pretty reasonably with shell highlights. :)
Signed-off-by: Andrew "Tianon" Page <admwiggin@gmail.com >
Upstream-commit: 62d3b1bf2e830b6cdf7c4df86d356d48b58b1ab0
Component: engine
2015-05-29 13:39:37 -07:00
Tianon Gravi
efadb1b4ee
Finally add precise/12.04 as a build-deb target
...
Ubuntu Precise has a number of warts that made it non-trivial to add initially, but I've managed to work through some of them and come up with a working build. Two important parts to note are that it has neither the `btrfs` nor the `devicemapper` graphdriver backends since `btrfs-tools` and `libdevmapper-dev` in the precise repositories are too ancient for them to even compile.
Signed-off-by: Andrew "Tianon" Page <admwiggin@gmail.com >
Upstream-commit: 98180b89543396c07c1f1ea420554fbcce31c513
Component: engine
2015-05-29 12:55:58 -07:00
Harald Albers
7e5bfe1810
Update bash completion for 1.7.0
...
Signed-off-by: Harald Albers <github@albersweb.de >
Upstream-commit: b2832dffe5563486dd9dec7ed1b0183a1f320a2e
Component: engine
2015-05-29 12:42:59 +02:00
David Calavera
0f1265a12c
Merge pull request #13539 from tianon/deb-ubuntu-wily
...
Add Ubuntu Wily (15.10) as a build-deb target
Upstream-commit: f99a96274254a8c861b654c1caf6062b7c23e1de
Component: engine
2015-05-28 11:01:27 -07:00
David Calavera
0faed528d2
Merge pull request #13039 from stevenbrichards/13031-Upstart
...
Fix check for upstart not detecting properly
Upstream-commit: 0256bbdebbc2fa7911c6e12bfae488fab7b30301
Component: engine
2015-05-28 10:38:55 -07:00
Steven Richards
5dd5db33a8
Fixes #13031 - Check for upstart or init is not detecting properly
...
This will now properly check whether /etc/init.d/docker or service docker is
invoking the script and respond to the user accordingly.
Signed-off-by: Steven Richards <steven@axiomzen.co >
Upstream-commit: e5ff643aed78fb5dfb5e3fef518dfe56b82b3023
Component: engine
2015-05-28 09:52:05 -07:00