mirror of
https://github.com/podman-container-tools/podman.git
synced 2026-09-10 09:37:52 +00:00
currently, setting any sort of resource limit in a pod does nothing. With the newly refactored creation process in c/common, podman ca now set resources at a pod level meaning that resource related flags can now be exposed to podman pod create. cgroupfs and systemd are both supported with varying completion. cgroupfs is a much simpler process and one that is virtually complete for all resource types, the flags now just need to be added. systemd on the other hand has to be handeled via the dbus api meaning that the limits need to be passed as recognized properties to systemd. The properties added so far are the ones that podman pod create supports as well as `cpuset-mems` as this will be the next flag I work on. Signed-off-by: Charlie Doern <cdoern@redhat.com>
42 lines
2.3 KiB
Text
42 lines
2.3 KiB
Text
libseccomp-golang: Releases
|
|
===============================================================================
|
|
https://github.com/seccomp/libseccomp-golang
|
|
|
|
* Version 0.10.0 - June 9, 2022
|
|
- Minimum supported version of libseccomp bumped to v2.3.1
|
|
- Add seccomp userspace notification API (ActNotify, filter.*Notif*)
|
|
- Add filter.{Get,Set}SSB (to support SCMP_FLTATR_CTL_SSB)
|
|
- Add filter.{Get,Set}Optimize (to support SCMP_FLTATR_CTL_OPTIMIZE)
|
|
- Add filter.{Get,Set}RawRC (to support SCMP_FLTATR_API_SYSRAWRC)
|
|
- Add ArchPARISC, ArchPARISC64, ArchRISCV64
|
|
- Add ActKillProcess and ActKillThread; deprecate ActKill
|
|
- Add go module support
|
|
- Return ErrSyscallDoesNotExist when unable to resolve a syscall
|
|
- Fix some functions to check for both kernel level API and libseccomp version
|
|
- Fix MakeCondition to use sanitizeCompareOp
|
|
- Fix AddRule to handle EACCES (from libseccomp >= 2.5.0)
|
|
- Updated the main docs and converted to README.md
|
|
- Added CONTRIBUTING.md, SECURITY.md, and administrative docs under doc/admin
|
|
- Add GitHub action CI, enable more linters
|
|
- test: test against various libseccomp versions
|
|
- test: fix and simplify execInSubprocess
|
|
- test: fix APILevelIsSupported
|
|
- Refactor the Errno(-1 * retCode) pattern
|
|
- Refactor/unify libseccomp version / API level checks
|
|
- Code cleanups (linter, formatting, spelling fixes)
|
|
- Cleanup: use errors.New instead of fmt.Errorf where appropriate
|
|
- Cleanup: remove duplicated cgo stuff, redundant linux build tag
|
|
|
|
* Version 0.9.1 - May 21, 2019
|
|
- Minimum supported version of libseccomp bumped to v2.2.0
|
|
- Use Libseccomp's `seccomp_version` API to retrieve library version
|
|
- Unconditionally set TSync attribute for filters, due to Go's heavily threaded nature
|
|
- Fix CVE-2017-18367 - Multiple syscall arguments were incorrectly combined with logical-OR, instead of logical-AND
|
|
- Fix a failure to build on Debian-based distributions due to CGo code
|
|
- Fix unit test failures on 32-bit architectures
|
|
- Improve several errors to be more verbose about their causes
|
|
- Add support for SCMP_ACT_LOG (with libseccomp versions 2.4.x and higher), permitting syscalls but logging their execution
|
|
- Add support for SCMP_FLTATR_CTL_LOG (with libseccomp versions 2.4.x and higher), logging not-allowed actions when they are denied
|
|
|
|
* Version 0.9.0 - January 5, 2017
|
|
- Initial tagged release
|