runtime-tools
runtime-tools copied to clipboard
seccomp: add CloneNewCgroup to check sysCloneFlagsIndex
All clone flags should be denied as default profile. Also x/sys should be used instead of syscall.
Signed-off-by: Kenta Tada [email protected]
I don't understand why pullapprove was failed but I signed off. Could you take a look at this commit?
FYI, @vbatts @crosbymichael
This commit is related to below.
https://github.com/containerd/containerd/pull/3314
https://github.com/moby/moby/pull/39308
@KentaTada can you please rebase this?
Rebased. Thanks.
close/reopen to kick ci