firecracker-microvm / firecracker-microvm/firecracker-containerd

Runtime SeccompProfilePath

Open
#98 0 comments 0 reactions 0 assignees View on GitHub
area/cri
Dominant language
Go
Stars
2.9k
Forks
247
PR merge metrics
No merged PRs in 30d

Description

- [ ] runtime should not block setting host name with unconfined seccomp and SYS_ADMIN
- [ ] should support seccomp unconfined on the container
- [ ] should support seccomp default which is unconfined on the container
- [ ] runtime should support setting hostname with docker/default seccomp profile and SYS_ADMIN
- [ ] runtime should support an seccomp profile that blocks setting hostname with SYS_ADMIN
- [ ] runtime should block sethostname with docker/default seccomp profile and no extra caps
- [ ] should support seccomp localhost/profile on the container
- [ ] runtime should not support a custom seccomp profile without using localhost/ as a prefix
- [ ] runtime should ignore a seccomp profile that blocks setting hostname when privileged
- [ ] should support seccomp docker/default on the container

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.