containerd/contrib
Sebastiaan van Stijn e1445dff12
profiles: seccomp: update to Linux 5.11 syscall list
These syscalls (some of which have been in Linux for a while but were
missing from the profile) fall into a few buckets:

 * close_range(2), epoll_wait2(2) are just extensions of existing "safe
   for everyone" syscalls.

 * The mountv2 API syscalls (fs*(2), move_mount(2), open_tree(2)) are
   all equivalent to aspects of mount(2) and thus go into the
   CAP_SYS_ADMIN category.

 * process_madvise(2) is similar to the other process_*(2) syscalls and
   thus goes in the CAP_SYS_PTRACE category.

Co-authored-by: Aleksa Sarai <asarai@suse.de>
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2021-01-21 21:30:25 +01:00
..
ansible docs: point cri release tarball to github release page 2021-01-03 17:50:40 +08:00
apparmor contrib/apparmor: expose LoadDefaultProfile 2020-12-11 19:59:51 +09:00
autocomplete Fix zsh autocomplete script 2020-02-11 19:56:27 +08:00
aws Move snapshotters benchmark to a separate package 2019-04-02 14:42:21 -07:00
gce Refractor the script to work in both python2 and python3 2020-09-11 13:53:33 -07:00
linuxkit contrib: add reference to LinuxKit project 2017-09-26 10:52:33 +01:00
nvidia fix mis-spelling in nvidia.go 2019-08-29 23:03:09 +08:00
seccomp profiles: seccomp: update to Linux 5.11 syscall list 2021-01-21 21:30:25 +01:00
snapshotservice Add Cleanup to snapshot API 2020-01-07 14:59:20 -08:00
Dockerfile.test Bump Golang 1.15.6 2021-01-12 16:44:36 -05:00
README.md Add readme to contib 2017-09-18 11:47:27 -04:00

contrib

The contrib directory contains packages that do not belong in the core containerd packages but still contribute to overall containerd usability.

Package such as Apparmor or Selinux are placed in contrib because they are platform dependent and often require higher level tools and profiles to work.

Packaging and other built tools can be added to contrib to aid in packaging containerd for various distributions.

Testing

Code in the contrib directory may or may not have been tested in the normal test pipeline for core components.