This repository has been archived by the owner on May 6, 2020. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 70
Evaluate use of capabilities in executables #51
Comments
jcvenegas
added a commit
to jcvenegas/cc-runtime
that referenced
this issue
Sep 27, 2017
** Changes - cc-check: Always run all tests - build: Fix config file warning message - list: Ensure "--cc-all" details are correct - refactor: simplify code to return the fastpath first - Unbreak gofmt - process: Add github issue template - paths: Resolve paths earlier - scripts: Improve collect data script - build: Show version of go - tests: Increase unit test timeout - build: Fix go vet issues flagged by go 1.9 - docs: developers: how to build custom kernel - scripts: Create script to gather environment details - readme: Update CI badges - ci: Remove Travis and add unit testing to all CI ** Shortlog 413e2ed cc-check: Only warn if nesting not available c761552 cc-check: Always run all tests 6ec4ecd build: Fix config file warning message b629d80 list: Ensure "--cc-all" details are correct 1378b68 refactor: simplify code to return the fastpath first fc87e7b tests: Fix gofmt and ineffassign issues 2212ef7 CI: Unbreak gofmt logic 651cfb3 process: Add github issue template 2c1ce71 paths: Resolve paths earlier 16b1dae scripts: Improve formatting in cc-collect-data.sh 53bd495 scripts: Simpify main function in cc-collect-data.sh 08ed990 scripts: Rename Meta heading in cc-collect-data.sh 57f2500 scripts: Use more punctuation in cc-collect-data.sh 6a7fc90 scripts: Add more patterns to cc-collect-data.sh 541fe44 scripts: Add more patterns to cc-collect-data.sh 1c7d20c build: Generate cc-collect script ffe6ccf build: Generalise ".in" file rule 9280a6b build: Show version of go 1bde169 tests: Increase unit test timeout d4954bc Revert: Undo "Merge pull request *587 from mcastelino/topic/govet" 5213667 go vet: Fix issues detected by go vet in go 1.9 acecd7b Revendor: Revendor testify to fix go vet 3d07c40 docs: developers: how to build custom kernel c8fc271 scripts: Create script to gather environment details 062522d readme: Update CI badges fb10a0e .ci: Remove travis and add unit testing to Jenkins ** Compatibility with Docker Clear Containers 3.0.1 is compatible with Docker v17.06-ce ** OCI Runtime Specification Clear Containers 3.0.1 support the OCI Runtime Specification [v1.0.0-rc5][ocispec] ** Clear Linux Containers image Clear Containers 3.0.1 requires at least Clear Linux containers image [17270][clearlinuximage] ** Clear Linux Containers Kernel Clear Containers 3.0.1 requires at least Clear Linux Containers kernel [v4.9.47-77.container][kernel] ** Installation - [Ubuntu][ubuntu] - [Fedora][fedora] - [Developers][developers] ** Issues & limitations *** Networking **** Adding networks dynamically *** Resource management **** `docker run --cpus=` See issue [\*341](clearcontainers#341) for more information. **** `docker run --kernel-memory=` See issue [\*388](clearcontainers#388) for more information. **** shm **** cgroup constraints **** Capabilities See issue [\*51](clearcontainers#51) for more information. **** sysctl **** tmpfs *** Other **** checkpoint and restore **** `docker stats` See issue [\*200](clearcontainers#200) for more information. *** runtime commands **** `ps` command See issue [\*95](clearcontainers#95) for more information. **** `events` command See issue [\*379](clearcontainers#379) for more information. **** `update` command See issue [\*380](clearcontainers#380) for more information. *** Networking **** Support for joining an existing VM network **** `docker --net=host` **** `docker run --link` *** Host resource sharing **** `docker --device` **** `docker -v /dev/...` **** `docker run --privileged` *** Other **** Annotations *** runtime commands **** `init` command **** `spec` command More information [Limitations][limitations] [clearlinuximage]: https://download.clearlinux.org/releases/17270/clear/clear-17270-containers.img.xz [kernel]: https://github.com/clearcontainers/linux/tree/v4.9.47-77.container [ocispec]: https://github.com/opencontainers/runtime-spec/releases/tag/v1.0.0-rc5 [limitations]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/limitations.md [ubuntu]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/ubuntu-installation-guide.md [fedora]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/fedora-installation-guide.md [developers]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/developers-clear-containers-install.md Signed-off-by: Jose Carlos Venegas Munoz <[email protected]>
jcvenegas
added a commit
to jcvenegas/cc-runtime
that referenced
this issue
Sep 27, 2017
** Changes - cc-check: Always run all tests - build: Fix config file warning message - list: Ensure "--cc-all" details are correct - refactor: simplify code to return the fastpath first - Unbreak gofmt - process: Add github issue template - paths: Resolve paths earlier - scripts: Improve collect data script - build: Show version of go - tests: Increase unit test timeout - build: Fix go vet issues flagged by go 1.9 - docs: developers: how to build custom kernel - scripts: Create script to gather environment details - readme: Update CI badges - ci: Remove Travis and add unit testing to all CI ** Shortlog 413e2ed cc-check: Only warn if nesting not available c761552 cc-check: Always run all tests 6ec4ecd build: Fix config file warning message b629d80 list: Ensure "--cc-all" details are correct 1378b68 refactor: simplify code to return the fastpath first fc87e7b tests: Fix gofmt and ineffassign issues 2212ef7 CI: Unbreak gofmt logic 651cfb3 process: Add github issue template 2c1ce71 paths: Resolve paths earlier 16b1dae scripts: Improve formatting in cc-collect-data.sh 53bd495 scripts: Simpify main function in cc-collect-data.sh 08ed990 scripts: Rename Meta heading in cc-collect-data.sh 57f2500 scripts: Use more punctuation in cc-collect-data.sh 6a7fc90 scripts: Add more patterns to cc-collect-data.sh 541fe44 scripts: Add more patterns to cc-collect-data.sh 1c7d20c build: Generate cc-collect script ffe6ccf build: Generalise ".in" file rule 9280a6b build: Show version of go 1bde169 tests: Increase unit test timeout d4954bc Revert: Undo "Merge pull request *587 from mcastelino/topic/govet" 5213667 go vet: Fix issues detected by go vet in go 1.9 acecd7b Revendor: Revendor testify to fix go vet 3d07c40 docs: developers: how to build custom kernel c8fc271 scripts: Create script to gather environment details 062522d readme: Update CI badges fb10a0e .ci: Remove travis and add unit testing to Jenkins ** Compatibility with Docker Clear Containers 3.0.1 is compatible with Docker v17.06-ce ** OCI Runtime Specification Clear Containers 3.0.1 support the OCI Runtime Specification [v1.0.0-rc5][ocispec] ** Clear Linux Containers image Clear Containers 3.0.1 requires at least Clear Linux containers image [17270][clearlinuximage] ** Clear Linux Containers Kernel Clear Containers 3.0.1 requires at least Clear Linux Containers kernel [v4.9.47-77.container][kernel] ** Installation - [Ubuntu][ubuntu] - [Fedora][fedora] - [Developers][developers] ** Issues & limitations *** Networking **** Adding networks dynamically *** Resource management **** `docker run --cpus=` See issue [\*341](clearcontainers#341) for more information. **** `docker run --kernel-memory=` See issue [\*388](clearcontainers#388) for more information. **** shm **** cgroup constraints **** Capabilities See issue [\*51](clearcontainers#51) for more information. **** sysctl **** tmpfs *** Other **** checkpoint and restore **** `docker stats` See issue [\*200](clearcontainers#200) for more information. *** runtime commands **** `ps` command See issue [\*95](clearcontainers#95) for more information. **** `events` command See issue [\*379](clearcontainers#379) for more information. **** `update` command See issue [\*380](clearcontainers#380) for more information. *** Networking **** Support for joining an existing VM network **** `docker --net=host` **** `docker run --link` *** Host resource sharing **** `docker --device` **** `docker -v /dev/...` **** `docker run --privileged` *** Other **** Annotations *** runtime commands **** `init` command **** `spec` command More information [Limitations][limitations] [clearlinuximage]: https://download.clearlinux.org/releases/17270/clear/clear-17270-containers.img.xz [kernel]: https://github.com/clearcontainers/linux/tree/v4.9.47-77.container [ocispec]: https://github.com/opencontainers/runtime-spec/releases/tag/v1.0.0-rc5 [limitations]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/limitations.md [ubuntu]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/ubuntu-installation-guide.md [fedora]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/fedora-installation-guide.md [developers]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/developers-clear-containers-install.md Fixes clearcontainers#640 Signed-off-by: Jose Carlos Venegas Munoz <[email protected]>
Merged
jcvenegas
added a commit
to jcvenegas/cc-runtime
that referenced
this issue
Sep 27, 2017
** Changes - cc-check: Always run all tests - build: Fix config file warning message - list: Ensure "--cc-all" details are correct - refactor: simplify code to return the fastpath first - Unbreak gofmt - process: Add github issue template - paths: Resolve paths earlier - scripts: Improve collect data script - build: Show version of go - tests: Increase unit test timeout - build: Fix go vet issues flagged by go 1.9 - docs: developers: how to build custom kernel - scripts: Create script to gather environment details - readme: Update CI badges - ci: Remove Travis and add unit testing to all CI ** Shortlog 413e2ed cc-check: Only warn if nesting not available c761552 cc-check: Always run all tests 6ec4ecd build: Fix config file warning message b629d80 list: Ensure "--cc-all" details are correct 1378b68 refactor: simplify code to return the fastpath first fc87e7b tests: Fix gofmt and ineffassign issues 2212ef7 CI: Unbreak gofmt logic 651cfb3 process: Add github issue template 2c1ce71 paths: Resolve paths earlier 16b1dae scripts: Improve formatting in cc-collect-data.sh 53bd495 scripts: Simpify main function in cc-collect-data.sh 08ed990 scripts: Rename Meta heading in cc-collect-data.sh 57f2500 scripts: Use more punctuation in cc-collect-data.sh 6a7fc90 scripts: Add more patterns to cc-collect-data.sh 541fe44 scripts: Add more patterns to cc-collect-data.sh 1c7d20c build: Generate cc-collect script ffe6ccf build: Generalise ".in" file rule 9280a6b build: Show version of go 1bde169 tests: Increase unit test timeout d4954bc Revert: Undo "Merge pull request *587 from mcastelino/topic/govet" 5213667 go vet: Fix issues detected by go vet in go 1.9 acecd7b Revendor: Revendor testify to fix go vet 3d07c40 docs: developers: how to build custom kernel c8fc271 scripts: Create script to gather environment details 062522d readme: Update CI badges fb10a0e .ci: Remove travis and add unit testing to Jenkins ** Compatibility with Docker Clear Containers 3.0.1 is compatible with Docker v17.06-ce ** OCI Runtime Specification Clear Containers 3.0.1 support the OCI Runtime Specification [v1.0.0-rc5][ocispec] ** Clear Linux Containers image Clear Containers 3.0.1 requires at least Clear Linux containers image [17270][clearlinuximage] ** Clear Linux Containers Kernel Clear Containers 3.0.1 requires at least Clear Linux Containers kernel [v4.9.47-77.container][kernel] ** Installation - [Ubuntu][ubuntu] - [Fedora][fedora] - [Developers][developers] ** Issues & limitations *** Networking **** Adding networks dynamically *** Resource management **** `docker run --cpus=` See issue [\*341](clearcontainers#341) for more information. **** `docker run --kernel-memory=` See issue [\*388](clearcontainers#388) for more information. **** shm **** cgroup constraints **** Capabilities See issue [\*51](clearcontainers#51) for more information. **** sysctl **** tmpfs *** Other **** checkpoint and restore **** `docker stats` See issue [\*200](clearcontainers#200) for more information. *** runtime commands **** `ps` command See issue [\*95](clearcontainers#95) for more information. **** `events` command See issue [\*379](clearcontainers#379) for more information. **** `update` command See issue [\*380](clearcontainers#380) for more information. *** Networking **** Support for joining an existing VM network **** `docker --net=host` **** `docker run --link` *** Host resource sharing **** `docker --device` **** `docker -v /dev/...` **** `docker run --privileged` *** Other **** Annotations *** runtime commands **** `init` command **** `spec` command More information [Limitations][limitations] [clearlinuximage]: https://download.clearlinux.org/releases/17270/clear/clear-17270-containers.img.xz [kernel]: https://github.com/clearcontainers/linux/tree/v4.9.47-77.container [ocispec]: https://github.com/opencontainers/runtime-spec/releases/tag/v1.0.0-rc5 [limitations]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/limitations.md [ubuntu]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/ubuntu-installation-guide.md [fedora]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/fedora-installation-guide.md [developers]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/developers-clear-containers-install.md Fixes clearcontainers#640 Signed-off-by: Jose Carlos Venegas Munoz <[email protected]>
jcvenegas
added a commit
to jcvenegas/cc-runtime
that referenced
this issue
Sep 27, 2017
** Changes - cc-check: Always run all tests - build: Fix config file warning message - list: Ensure "--cc-all" details are correct - refactor: simplify code to return the fastpath first - Unbreak gofmt - process: Add github issue template - paths: Resolve paths earlier - scripts: Improve collect data script - build: Show version of go - tests: Increase unit test timeout - build: Fix go vet issues flagged by go 1.9 - docs: developers: how to build custom kernel - scripts: Create script to gather environment details - readme: Update CI badges - ci: Remove Travis and add unit testing to all CI ** Shortlog 413e2ed cc-check: Only warn if nesting not available c761552 cc-check: Always run all tests 6ec4ecd build: Fix config file warning message b629d80 list: Ensure "--cc-all" details are correct 1378b68 refactor: simplify code to return the fastpath first fc87e7b tests: Fix gofmt and ineffassign issues 2212ef7 CI: Unbreak gofmt logic 651cfb3 process: Add github issue template 2c1ce71 paths: Resolve paths earlier 16b1dae scripts: Improve formatting in cc-collect-data.sh 53bd495 scripts: Simpify main function in cc-collect-data.sh 08ed990 scripts: Rename Meta heading in cc-collect-data.sh 57f2500 scripts: Use more punctuation in cc-collect-data.sh 6a7fc90 scripts: Add more patterns to cc-collect-data.sh 541fe44 scripts: Add more patterns to cc-collect-data.sh 1c7d20c build: Generate cc-collect script ffe6ccf build: Generalise ".in" file rule 9280a6b build: Show version of go 1bde169 tests: Increase unit test timeout d4954bc Revert: Undo "Merge pull request *587 from mcastelino/topic/govet" 5213667 go vet: Fix issues detected by go vet in go 1.9 acecd7b Revendor: Revendor testify to fix go vet 3d07c40 docs: developers: how to build custom kernel c8fc271 scripts: Create script to gather environment details 062522d readme: Update CI badges fb10a0e .ci: Remove travis and add unit testing to Jenkins ** Compatibility with Docker Clear Containers 3.0.1 is compatible with Docker v17.06-ce ** OCI Runtime Specification Clear Containers 3.0.1 support the OCI Runtime Specification [v1.0.0-rc5][ocispec] ** Clear Linux Containers image Clear Containers 3.0.1 requires at least Clear Linux containers image [17270][clearlinuximage] ** Clear Linux Containers Kernel Clear Containers 3.0.1 requires at least Clear Linux Containers kernel [v4.9.47-77.container][kernel] ** Installation - [Ubuntu][ubuntu] - [Fedora][fedora] - [Developers][developers] ** Issues & limitations *** Networking **** Adding networks dynamically *** Resource management **** `docker run --cpus=` See issue [\*341](clearcontainers#341) for more information. **** `docker run --kernel-memory=` See issue [\*388](clearcontainers#388) for more information. **** shm **** cgroup constraints **** Capabilities See issue [\*51](clearcontainers#51) for more information. **** sysctl **** tmpfs *** Other **** checkpoint and restore **** `docker stats` See issue [\*200](clearcontainers#200) for more information. *** runtime commands **** `ps` command See issue [\*95](clearcontainers#95) for more information. **** `events` command See issue [\*379](clearcontainers#379) for more information. **** `update` command See issue [\*380](clearcontainers#380) for more information. *** Networking **** Support for joining an existing VM network **** `docker --net=host` **** `docker run --link` *** Host resource sharing **** `docker --device` **** `docker -v /dev/...` **** `docker run --privileged` *** Other **** Annotations *** runtime commands **** `init` command **** `spec` command More information [Limitations][limitations] [clearlinuximage]: https://download.clearlinux.org/releases/17270/clear/clear-17270-containers.img.xz [kernel]: https://github.com/clearcontainers/linux/tree/v4.9.47-77.container [ocispec]: https://github.com/opencontainers/runtime-spec/releases/tag/v1.0.0-rc5 [limitations]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/limitations.md [ubuntu]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/ubuntu-installation-guide.md [fedora]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/fedora-installation-guide.md [developers]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/developers-clear-containers-install.md Fixes clearcontainers#640 Signed-off-by: Jose Carlos Venegas Munoz <[email protected]>
jcvenegas
added a commit
to jcvenegas/cc-runtime
that referenced
this issue
Sep 27, 2017
** Changes - cc-check: Always run all tests - build: Fix config file warning message - list: Ensure "--cc-all" details are correct - refactor: simplify code to return the fastpath first - Unbreak gofmt - process: Add github issue template - paths: Resolve paths earlier - scripts: Improve collect data script - build: Show version of go - tests: Increase unit test timeout - build: Fix go vet issues flagged by go 1.9 - docs: developers: how to build custom kernel - scripts: Create script to gather environment details - readme: Update CI badges - ci: Remove Travis and add unit testing to all CI ** Shortlog 413e2ed cc-check: Only warn if nesting not available c761552 cc-check: Always run all tests 6ec4ecd build: Fix config file warning message b629d80 list: Ensure "--cc-all" details are correct 1378b68 refactor: simplify code to return the fastpath first fc87e7b tests: Fix gofmt and ineffassign issues 2212ef7 CI: Unbreak gofmt logic 651cfb3 process: Add github issue template 2c1ce71 paths: Resolve paths earlier 16b1dae scripts: Improve formatting in cc-collect-data.sh 53bd495 scripts: Simpify main function in cc-collect-data.sh 08ed990 scripts: Rename Meta heading in cc-collect-data.sh 57f2500 scripts: Use more punctuation in cc-collect-data.sh 6a7fc90 scripts: Add more patterns to cc-collect-data.sh 541fe44 scripts: Add more patterns to cc-collect-data.sh 1c7d20c build: Generate cc-collect script ffe6ccf build: Generalise ".in" file rule 9280a6b build: Show version of go 1bde169 tests: Increase unit test timeout d4954bc Revert: Undo "Merge pull request *587 from mcastelino/topic/govet" 5213667 go vet: Fix issues detected by go vet in go 1.9 acecd7b Revendor: Revendor testify to fix go vet 3d07c40 docs: developers: how to build custom kernel c8fc271 scripts: Create script to gather environment details 062522d readme: Update CI badges fb10a0e .ci: Remove travis and add unit testing to Jenkins ** Compatibility with Docker Clear Containers 3.0.1 is compatible with Docker v17.06-ce ** OCI Runtime Specification Clear Containers 3.0.1 support the OCI Runtime Specification [v1.0.0-rc5][ocispec] ** Clear Linux Containers image Clear Containers 3.0.1 requires at least Clear Linux containers image [17270][clearlinuximage] ** Clear Linux Containers Kernel Clear Containers 3.0.1 requires at least Clear Linux Containers kernel [v4.9.47-77.container][kernel] ** Installation - [Ubuntu][ubuntu] - [Fedora][fedora] - [Developers][developers] ** Issues & limitations *** Networking **** Adding networks dynamically *** Resource management **** `docker run --cpus=` See issue [\*341](clearcontainers#341) for more information. **** `docker run --kernel-memory=` See issue [\*388](clearcontainers#388) for more information. **** shm **** cgroup constraints **** Capabilities See issue [\*51](clearcontainers#51) for more information. **** sysctl **** tmpfs *** Other **** checkpoint and restore **** `docker stats` See issue [\*200](clearcontainers#200) for more information. *** runtime commands **** `ps` command See issue [\*95](clearcontainers#95) for more information. **** `events` command See issue [\*379](clearcontainers#379) for more information. **** `update` command See issue [\*380](clearcontainers#380) for more information. *** Networking **** Support for joining an existing VM network **** `docker --net=host` **** `docker run --link` *** Host resource sharing **** `docker --device` **** `docker -v /dev/...` **** `docker run --privileged` *** Other **** Annotations *** runtime commands **** `init` command **** `spec` command More information [Limitations][limitations] [clearlinuximage]: https://download.clearlinux.org/releases/17270/clear/clear-17270-containers.img.xz [kernel]: https://github.com/clearcontainers/linux/tree/v4.9.47-77.container [ocispec]: https://github.com/opencontainers/runtime-spec/releases/tag/v1.0.0-rc5 [limitations]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/limitations.md [ubuntu]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/ubuntu-installation-guide.md [fedora]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/fedora-installation-guide.md [developers]: https://github.com/clearcontainers/runtime/blob/f5bc403510ab2a837ba4b2115ea4c94cf51e9dea/docs/developers-clear-containers-install.md Fixes clearcontainers#640 Signed-off-by: Jose Carlos Venegas Munoz <[email protected]>
Merged
Merged
This was referenced Nov 29, 2017
Merged
Merged
Merged
Merged
Merged
Merged
Merged
Merged
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
We should probably do a review of our executables 'capabilities', and start to remove any that are not needed (to reduce attack surface).
On the host side we should check what we can do for:
and on the guest side we probably need to set or remove the capabilities around the workload according to the configuration (from the OCI file for instance) that is passed in/requested of us.
The text was updated successfully, but these errors were encountered: