Skip to content

Commit 364ec0f

Browse files
committed
runc: do not set inheritable capabilities
Do not set inheritable capabilities in runc spec, runc exec --cap, and in libcontainer integration tests. Signed-off-by: Kir Kolyshkin <[email protected]>
1 parent 5854665 commit 364ec0f

File tree

5 files changed

+0
-40
lines changed

5 files changed

+0
-40
lines changed

exec.go

-1
Original file line numberDiff line numberDiff line change
@@ -224,7 +224,6 @@ func getProcess(context *cli.Context, bundle string) (*specs.Process, error) {
224224
if caps := context.StringSlice("cap"); len(caps) > 0 {
225225
for _, c := range caps {
226226
p.Capabilities.Bounding = append(p.Capabilities.Bounding, c)
227-
p.Capabilities.Inheritable = append(p.Capabilities.Inheritable, c)
228227
p.Capabilities.Effective = append(p.Capabilities.Effective, c)
229228
p.Capabilities.Permitted = append(p.Capabilities.Permitted, c)
230229
p.Capabilities.Ambient = append(p.Capabilities.Ambient, c)

libcontainer/README.md

-16
Original file line numberDiff line numberDiff line change
@@ -96,22 +96,6 @@ config := &configs.Config{
9696
"CAP_KILL",
9797
"CAP_AUDIT_WRITE",
9898
},
99-
Inheritable: []string{
100-
"CAP_CHOWN",
101-
"CAP_DAC_OVERRIDE",
102-
"CAP_FSETID",
103-
"CAP_FOWNER",
104-
"CAP_MKNOD",
105-
"CAP_NET_RAW",
106-
"CAP_SETGID",
107-
"CAP_SETUID",
108-
"CAP_SETFCAP",
109-
"CAP_SETPCAP",
110-
"CAP_NET_BIND_SERVICE",
111-
"CAP_SYS_CHROOT",
112-
"CAP_KILL",
113-
"CAP_AUDIT_WRITE",
114-
},
11599
Permitted: []string{
116100
"CAP_CHOWN",
117101
"CAP_DAC_OVERRIDE",

libcontainer/integration/exec_test.go

-2
Original file line numberDiff line numberDiff line change
@@ -364,7 +364,6 @@ func TestProcessCaps(t *testing.T) {
364364
pconfig.Capabilities.Bounding = append(config.Capabilities.Bounding, "CAP_NET_ADMIN")
365365
pconfig.Capabilities.Permitted = append(config.Capabilities.Permitted, "CAP_NET_ADMIN")
366366
pconfig.Capabilities.Effective = append(config.Capabilities.Effective, "CAP_NET_ADMIN")
367-
pconfig.Capabilities.Inheritable = append(config.Capabilities.Inheritable, "CAP_NET_ADMIN")
368367
err = container.Run(&pconfig)
369368
ok(t, err)
370369

@@ -1409,7 +1408,6 @@ func TestRootfsPropagationSharedMount(t *testing.T) {
14091408
pconfig2.Capabilities.Bounding = append(config.Capabilities.Bounding, "CAP_SYS_ADMIN")
14101409
pconfig2.Capabilities.Permitted = append(config.Capabilities.Permitted, "CAP_SYS_ADMIN")
14111410
pconfig2.Capabilities.Effective = append(config.Capabilities.Effective, "CAP_SYS_ADMIN")
1412-
pconfig2.Capabilities.Inheritable = append(config.Capabilities.Inheritable, "CAP_SYS_ADMIN")
14131411

14141412
err = container.Run(pconfig2)
14151413
_ = stdinR2.Close()

libcontainer/integration/template_test.go

-16
Original file line numberDiff line numberDiff line change
@@ -75,22 +75,6 @@ func newTemplateConfig(t *testing.T, p *tParam) *configs.Config {
7575
"CAP_KILL",
7676
"CAP_AUDIT_WRITE",
7777
},
78-
Inheritable: []string{
79-
"CAP_CHOWN",
80-
"CAP_DAC_OVERRIDE",
81-
"CAP_FSETID",
82-
"CAP_FOWNER",
83-
"CAP_MKNOD",
84-
"CAP_NET_RAW",
85-
"CAP_SETGID",
86-
"CAP_SETUID",
87-
"CAP_SETFCAP",
88-
"CAP_SETPCAP",
89-
"CAP_NET_BIND_SERVICE",
90-
"CAP_SYS_CHROOT",
91-
"CAP_KILL",
92-
"CAP_AUDIT_WRITE",
93-
},
9478
Ambient: []string{
9579
"CAP_CHOWN",
9680
"CAP_DAC_OVERRIDE",

libcontainer/specconv/example.go

-5
Original file line numberDiff line numberDiff line change
@@ -41,11 +41,6 @@ func Example() *specs.Spec {
4141
"CAP_KILL",
4242
"CAP_NET_BIND_SERVICE",
4343
},
44-
Inheritable: []string{
45-
"CAP_AUDIT_WRITE",
46-
"CAP_KILL",
47-
"CAP_NET_BIND_SERVICE",
48-
},
4944
Ambient: []string{
5045
"CAP_AUDIT_WRITE",
5146
"CAP_KILL",

0 commit comments

Comments
 (0)