Skip to content
This repository has been archived by the owner on Oct 13, 2023. It is now read-only.

[19.03 backport] rootless: harden slirp4netns with mount namespace and seccomp #397

Merged

Conversation

thaJeztah
Copy link
Member

@thaJeztah thaJeztah commented Oct 5, 2019

backport of moby#39840

When slirp4netns v0.4.0+ is used, now slirp4netns is hardened using
mount namespace ("sandbox") and seccomp to mitigate potential
vulnerabilities.

bump up rootlesskit: rootless-containers/rootlesskit@2fcff6c...791ac8c

- Description for the changelog

* Update to RootlessKit to v0.7.0 to harden slirp4netns with mount namespace and seccomp

- A picture of a cute animal (not mandatory but encouraged)

When slirp4netns v0.4.0+ is used, now slirp4netns is hardened using
mount namespace ("sandbox") and seccomp to mitigate potential
vulnerabilities.

bump up rootlesskit: rootless-containers/rootlesskit@2fcff6c...791ac8c

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
(cherry picked from commit e20b732)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
@thaJeztah thaJeztah added this to the 19.03.4 milestone Oct 5, 2019
@thaJeztah
Copy link
Member Author

ping @AkihiroSuda @tiborvass ptal

@thaJeztah thaJeztah modified the milestones: 19.03.4, 19.03.5 Oct 11, 2019
Copy link

@andrewhsu andrewhsu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@andrewhsu andrewhsu merged commit d91a85a into docker-archive:19.03 Oct 28, 2019
@thaJeztah thaJeztah deleted the 19.03_backport_slirp4netns_sandbox branch October 28, 2019 17:45
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants