spiegel_podman/pkg/specgen
Giuseppe Scrivano 8292fc0a44 do not set the inheritable capabilities
The kernel never sets the inheritable capabilities for a process, they
are only set by userspace.  Emulate the same behavior.

Closes: CVE-2022-27649

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
(cherry picked from commit aafa80918a)
2022-04-12 14:27:41 -04:00
..
generate do not set the inheritable capabilities 2022-04-12 14:27:41 -04:00
config_unsupported.go migrate Podman to containers/common/libimage 2021-05-05 11:30:12 +02:00
container_validate.go bump go module to v3 2021-02-22 09:03:51 +01:00
namespaces.go Add support for pod inside of user namespace. 2021-08-09 15:17:22 -04:00
pod_validate.go --infra-name command line argument 2021-07-15 21:27:51 -03:00
podspecgen.go InfraContainer Rework 2021-08-26 16:05:16 -04:00
specgen.go secret: honor custom target for secrets with run 2021-12-06 14:37:46 -05:00
volumes.go libpod/option.go remove error stutter from wrap/wraf 2021-08-17 16:14:02 +05:30