Skip to content

Commit 38d7d98

Browse files
Merge branch 'master' into security_fixes
2 parents 6fb781b + 436c21e commit 38d7d98

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

containerd/containerd.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ func (d *Driver) createContainer(containerConfig *ContainerConfig, config *TaskC
149149

150150
// Enable privileged mode.
151151
if config.Privileged {
152-
opts = append(opts, oci.WithPrivileged)
152+
opts = append(opts, oci.WithPrivileged, oci.WithAllDevicesAllowed, oci.WithHostDevices, oci.WithNewPrivileges)
153153
}
154154

155155
// WithPidsLimit sets the container's pid limit or maximum

tests/004-test-privileged.sh

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ test_privileged_nomad_job() {
4141
# depending on the execution environment.
4242
expected_capabilities="37"
4343
if [[ "$GITHUB_ACTIONS" == "true" ]]; then
44-
expected_capabilities="39"
44+
expected_capabilities="40"
4545
fi
4646

4747
actual_capabilities=$(nomad alloc exec -job privileged capsh --print|grep -i bounding|cut -d '=' -f 2|awk '{split($0,a,","); print a[length(a)]}')

0 commit comments

Comments
 (0)