This repository has been archived by the owner on May 12, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 113
Explicitly deny any access to the nvdimm root partition #791
Labels
Comments
amshinde
added
bug
Incorrect behaviour
needs-review
Needs to be assessed by the team.
labels
Jun 3, 2020
amshinde
added a commit
to amshinde/agent-1
that referenced
this issue
Jun 3, 2020
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com>
amshinde
added a commit
to amshinde/agent-1
that referenced
this issue
Jun 3, 2020
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com>
amshinde
added a commit
to amshinde/agent-1
that referenced
this issue
Jun 3, 2020
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com> (cherry picked from commit a88af32)
amshinde
added a commit
to amshinde/agent-1
that referenced
this issue
Jun 3, 2020
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com> (cherry picked from commit a88af32)
amshinde
added a commit
to amshinde/agent-1
that referenced
this issue
Jun 3, 2020
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com> (cherry picked from commit a88af32)
# for free
to subscribe to this conversation on GitHub.
Already have an account?
#.
Explicitly deny any access to the nvdimm root partition by adding the nvdimm device to the device cgroup.
The text was updated successfully, but these errors were encountered: