]> git.proxmox.com Git - mirror_lxc.git/commitdiff
config: start with a full capability set
authorChristian Brauner <christian.brauner@ubuntu.com>
Thu, 1 Mar 2018 16:09:44 +0000 (17:09 +0100)
committerChristian Brauner <christian.brauner@ubuntu.com>
Thu, 1 Mar 2018 16:09:44 +0000 (17:09 +0100)
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
config/templates/userns.conf.in

index be4fbbc6beee06524597e9b45b7d49416aa19fc2..967576b4c83210a0f6601e0f77173931a58f796f 100644 (file)
@@ -2,5 +2,9 @@
 lxc.cgroup.devices.deny =
 lxc.cgroup.devices.allow =
 
+# Start with a full set of capabilities in user namespaces.
+lxc.cap.drop =
+lxc.cap.keep =
+
 # We can't move bind-mounts, so don't use /dev/lxc/
 lxc.tty.dir =