containerd/contrib
Florian Schmaus e977564a8b seccomp: allow 'rseq' syscall in default seccomp profile
Restartable Sequences (rseq) are a kernel-based mechanism for fast
update operations on per-core data in user-space. Some libraries, like
the newest version of Google's TCMalloc, depend on it [1].

This also makes dockers default seccomp profile on par with systemd's,
which enabled 'rseq' in early 2019 [2].

1: https://google.github.io/tcmalloc/design.html
2: systemd/systemd@6fee3be

Signed-off-by: Florian Schmaus <flo@geekplace.eu>
2020-06-26 17:10:05 +02:00
..
apparmor explicitly fail apparmor when !linux 2020-06-22 12:54:09 -04:00
autocomplete Fix zsh autocomplete script 2020-02-11 19:56:27 +08:00
aws Move snapshotters benchmark to a separate package 2019-04-02 14:42:21 -07:00
nvidia fix mis-spelling in nvidia.go 2019-08-29 23:03:09 +08:00
seccomp seccomp: allow 'rseq' syscall in default seccomp profile 2020-06-26 17:10:05 +02:00
snapshotservice Add Cleanup to snapshot API 2020-01-07 14:59:20 -08:00
Dockerfile.test Bump Golang 1.13.12 2020-06-22 16:49:31 +09:00
README.md Add readme to contib 2017-09-18 11:47:27 -04:00

contrib

The contrib directory contains packages that do not belong in the core containerd packages but still contribute to overall containerd usability.

Package such as Apparmor or Selinux are placed in contrib because they are platform dependent and often require higher level tools and profiles to work.

Packaging and other built tools can be added to contrib to aid in packaging containerd for various distributions.

Testing

Code in the contrib directory may or may not have been tested in the normal test pipeline for core components.