-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Open
Description
When we were introducing dmz to runc, we have realized that there were 3 reasons we should disable runc-dmz:
- runc-dmz does not play well with selinux #4057, fixed by Add selinux-vs-dmz test case and a workaround #4053.
- The container process has a
CAP_SYS_PTRACEability, fixed by nsexec: cloned binary rework #3987. - If the container process is not root and the capabilities are not in the ambient set #4125, will be fixed by dmz: don't use runc-dmz in complicated capability setups #4137.
Maybe there are some more scenarios that can't use runc-dmz, please provide to help us improve or deprecate it. Thanks.
Metadata
Metadata
Assignees
Labels
No labels