Skip to content
Commit 9a71b112 authored by Jay Faulkner's avatar Jay Faulkner Committed by Zbigniew Jędrzejewski-Szmek
Browse files

nspawn: Map all seccomp filters to capabilities



This change makes it so all seccomp filters are mapped
to the appropriate capability and are only added if that
capability was not requested when running the container.

This unbreaks the remaining use cases broken by the
addition of seccomp filters without respecting requested
capabilities.

Co-Authored-By: default avatarClif Houck <me@clifhouck.com>

[zj: - adapt to our coding style, make struct anonymous]
parent 9e4ded30
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment