|
Zbigniew Jędrzejewski-Szmek |
f1004d |
From 864e17068ce9acf418d42a625141884293170952 Mon Sep 17 00:00:00 2001
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
From: Lennart Poettering <lennart@poettering.net>
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
Date: Fri, 10 Oct 2014 11:11:25 +0200
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
Subject: [PATCH] nspawn: actually allow access to /dev/net/tun in the
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
container
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
It's not sufficient to just copy the device node over, we need to update
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
the policy for it too.
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
---
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
src/nspawn/nspawn.c | 1 +
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
1 file changed, 1 insertion(+)
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
diff --git a/src/nspawn/nspawn.c b/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
index da4c116f36..f04d326131 100644
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
--- a/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
+++ b/src/nspawn/nspawn.c
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
@@ -1558,6 +1558,7 @@ static int register_machine(pid_t pid, int local_ifindex) {
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
"/dev/random", "rwm",
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
"/dev/urandom", "rwm",
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
"/dev/tty", "rwm",
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
+ "/dev/net/tun", "rwm",
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
/* Allow the container
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
* access to ptys. However,
|
|
Zbigniew Jędrzejewski-Szmek |
f1004d |
* do not permit the
|