containers / containers/bubblewrap
Default behaviour of `--cap-drop`
Open
- Dominant language
- C
- Stars
- 8.7k
- Forks
- 386
- Avg merge
- 3d 17h
- Merged PRs (30d)
- 11
Description
The documentation of `--cap-drop` states:
By default no caps are left in the sandboxed process.
That seems not to be true:
id
uid=0(root) gid=0(root) groups=0(root)
getpcaps $$
14257: =ep
bwrap --bind / / sh -c 'getpcaps $$'
15598: =ep
bwrap --bind / / --cap-drop ALL sh -c 'getpcaps $$'
15577: =
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.