ubuntu template: disallow cap_sys_module (by popular demand)

This isn't particularly reassuring, and will be moot with user
namespaces, but as people are asking for it, turn off sys_module.
While we're at it, turn off mac_admin and mac_override.

Signed-off-by: Serge Hallyn <serge.hallyn@canonical.com>
Signed-off-by: Daniel Lezcano <dlezcano@fr.ibm.com>
This commit is contained in:
Serge E. Hallyn 2011-10-24 14:38:30 +02:00 committed by Daniel Lezcano
parent 0f3fe9e0b5
commit cdcee3c7ff

View File

@ -179,6 +179,7 @@ lxc.pts = 1024
lxc.rootfs = $rootfs
lxc.mount = $path/fstab
lxc.arch = $arch
lxc.cap.drop = sys_module mac_override mac_admin
lxc.cgroup.devices.deny = a
# /dev/null and zero