The source project of this merge request has been removed.
Add some capabilities and system calls to arch-nspawn
Vairious testsuite failures in glibc are caused by default restrictions in system-nspawn. Adding the following allows the glibc testsuite to pass:
--system-call-filter="@clock @memlock @pkey"
Signed-off-by: Allan McRae allan@archlinux.org
Edited by Allan McRae
Merge request reports
Activity
added 1 commit
- 72c9dfcf - Add some capabilities and system calls to arch-nspawn
added 1 commit
- 779b01aa - Add some capabilities and system calls to arch-nspawn
@anthraxx any comments on the security implications of the options added?
mentioned in merge request !172 (merged)
Please register or sign in to reply