Re: [lxc-devel] [PATCH] oracle template: restrict writeability in /proc and /sys

2013-10-23 Thread Serge Hallyn
Quoting Dwight Engen (dwight.en...@oracle.com): > Note that since we don't drop CAP_SYS_ADMIN, root in the container can > remount proc or sys however they want to, however this at least improves > the default situation. > > Signed-off-by: Dwight Engen Acked-by: Serge E. Hallyn > --- > templa

[lxc-devel] [PATCH] oracle template: restrict writeability in /proc and /sys

2013-10-23 Thread Dwight Engen
Note that since we don't drop CAP_SYS_ADMIN, root in the container can remount proc or sys however they want to, however this at least improves the default situation. Signed-off-by: Dwight Engen --- templates/lxc-oracle.in | 7 +-- 1 file changed, 1 insertion(+), 6 deletions(-) diff --git a