<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="/source/rss.xsl.xml"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
    <title>Changes in common.seccomp</title>
    <link>http://src.iws.cs.ovgu.de/source/rss/lxc/config/templates/common.seccomp</link>
    <description></description>
    <language>en</language>
    <copyright>Copyright 2005</copyright>
    <generator>Java</generator>
    <item>
        <title>seccomp: add rule to reject umount -f
    
    If a container has a bind mount from a host nfs or fuse
    filesystem, and does 'umount -f', it will disconnect the
    host's filesystem.  This patch adds a seccomp rule to
    block umount -f from a container.  It also adds that rule
    to the default seccomp profile.
    
    Thanks stgraber for the idea :)
    
    Signed-off-by: Serge Hallyn &lt;serge.hallyn@ubuntu.com&gt;
    Acked-by: Stéphane Graber &lt;stgraber@ubuntu.com&gt;</title>
        <description>/lxc/config/templates/common.seccomp - 6166fa6d83b23e86a24cc2ab5cfe780fccb0a709</description>
        <pubDate></pubDate>
        <dc:creator>Serge Hallyn &lt;serge.hallyn@ubuntu.com&gt;</dc:creator>
    </item>

    <item>
        <title>Enable default seccomp profile for all distros
    
    This updates the common config to include Serge's seccomp profile by
    default for privileged containers.
    
    Signed-off-by: Stéphane Graber &lt;stgraber@ubuntu.com&gt;
    Acked-by: Serge E. Hallyn &lt;serge.hallyn@ubuntu.com&gt;</title>
        <description>/lxc/config/templates/common.seccomp - 6e39e4cbff5d49b4a66451696aa87b9884f58a6e</description>
        <pubDate></pubDate>
        <dc:creator>Stéphane Graber  &lt;stgraber@ubuntu.com&gt;</dc:creator>
    </item>

</channel>
</rss>

