containerd/contrib
Akihiro Suda 55923daa9f
seccomp: support "clone3" (return ENOSYS unless SYS_ADMIN is granted)
clone3 is explicitly requested to give ENOSYS instead of the default EPERM, when CAP_SYS_ADMIN is unset.
See moby/moby PR 42681 (thanks to berrange).

Without this commit, rawhide image does not work:
```console
$ sudo ctr run --rm --net-host --seccomp registry.fedoraproject.org/fedora:rawhide foo /usr/bin/curl google.com
curl: (6) getaddrinfo() thread failed to start
```

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2021-09-15 14:44:45 +09:00
..
ansible Update Pause image in tests & config 2021-08-31 19:42:57 +03:00
apparmor replace uses of os/exec with golang.org/x/sys/execabs 2021-08-25 18:11:09 +02:00
autocomplete Fix zsh autocomplete script 2020-02-11 19:56:27 +08:00
aws Move snapshotters benchmark to a separate package 2019-04-02 14:42:21 -07:00
Dockerfile.test.d/cri-in-userns Dockerfile.test: add "cri-in-userns" (aka rootless) test stage 2021-07-09 14:50:04 +09:00
fuzz Merge pull request #5906 from thaJeztah/replace_os_exec 2021-09-11 10:38:53 +08:00
gce Add env for SystemdCgroup driver 2021-08-16 17:27:55 +05:30
linuxkit update linuxkit readme 2021-03-01 12:00:56 +08:00
nvidia replace uses of os/exec with golang.org/x/sys/execabs 2021-08-25 18:11:09 +02:00
seccomp seccomp: support "clone3" (return ENOSYS unless SYS_ADMIN is granted) 2021-09-15 14:44:45 +09:00
snapshotservice Add Cleanup to snapshot API 2020-01-07 14:59:20 -08:00
Dockerfile.test Update to Go 1.17.1 2021-09-14 09:12:00 -04:00
README.md Add readme to contib 2017-09-18 11:47:27 -04:00

contrib

The contrib directory contains packages that do not belong in the core containerd packages but still contribute to overall containerd usability.

Package such as Apparmor or Selinux are placed in contrib because they are platform dependent and often require higher level tools and profiles to work.

Packaging and other built tools can be added to contrib to aid in packaging containerd for various distributions.

Testing

Code in the contrib directory may or may not have been tested in the normal test pipeline for core components.