Erase ambient capabilities.
Signed-off-by: Lantao Liu <lantaol@google.com>
This commit is contained in:
@@ -261,6 +261,7 @@ func TestContainerCapabilities(t *testing.T) {
|
||||
assert.NotContains(t, spec.Process.Capabilities.Inheritable, exclude)
|
||||
assert.NotContains(t, spec.Process.Capabilities.Permitted, exclude)
|
||||
}
|
||||
assert.Empty(t, spec.Process.Capabilities.Ambient)
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user