Fix privileged devices.

Signed-off-by: Lantao Liu <lantaol@google.com>
This commit is contained in:
Lantao Liu 2019-12-09 17:42:14 -08:00
parent 78708b20c7
commit 0c2d3b718d

View File

@ -170,7 +170,7 @@ func (c *criService) containerSpec(id string, sandboxID string, sandboxPid uint3
} }
specOpts = append(specOpts, oci.WithPrivileged) specOpts = append(specOpts, oci.WithPrivileged)
if !ociRuntime.PrivilegedWithoutHostDevices { if !ociRuntime.PrivilegedWithoutHostDevices {
specOpts = append(specOpts, oci.WithHostDevices) specOpts = append(specOpts, oci.WithHostDevices, oci.WithAllDevicesAllowed)
} }
} else { // not privileged } else { // not privileged
specOpts = append(specOpts, customopts.WithDevices(c.os, config), customopts.WithCapabilities(securityContext)) specOpts = append(specOpts, customopts.WithDevices(c.os, config), customopts.WithCapabilities(securityContext))