mirror of
https://git.proxmox.com/git/mirror_lxc
synced 2025-07-27 11:13:50 +00:00
attach_options: add LXC_ATTACH_NO_NEW_PRIVS
Add a flag for PR_SET_NO_NEW_PRIVS. It is off by default. Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
This commit is contained in:
parent
029cdff582
commit
1325da7eae
@ -49,6 +49,8 @@ enum {
|
||||
/* the following are off by default */
|
||||
LXC_ATTACH_REMOUNT_PROC_SYS = 0x00010000, //!< Remount /proc filesystem
|
||||
LXC_ATTACH_LSM_NOW = 0x00020000, //!< FIXME: unknown
|
||||
/* Set PR_SET_NO_NEW_PRIVS to block execve() gainable privileges. */
|
||||
LXC_ATTACH_NO_NEW_PRIVS = 0x00040000, //!< PR_SET_NO_NEW_PRIVS
|
||||
|
||||
/* we have 16 bits for things that are on by default
|
||||
* and 16 bits that are off by default, that should
|
||||
|
Loading…
Reference in New Issue
Block a user