commit | a21ecdf3c8a343a7c94e4c4d01b178c87ca7aaa1 | [log] [tgz] |
---|---|---|
author | Justin Cormack <justin.cormack@docker.com> | Fri Nov 03 15:12:22 2017 +0000 |
committer | Justin Cormack <justin.cormack@docker.com> | Fri Nov 03 15:12:22 2017 +0000 |
tree | 6ac9206d8f8afb39f9925076cb410e587fafb5c5 | |
parent | 7801be2eee987013cc20148d0335f42bec618835 [diff] |
Add /proc/scsi to masked paths This is writeable, and can be used to remove devices. Containers do not need to know about scsi devices. Signed-off-by: Justin Cormack <justin.cormack@docker.com>
diff --git a/oci/defaults.go b/oci/defaults.go index 0cc07ff..4188071 100644 --- a/oci/defaults.go +++ b/oci/defaults.go
@@ -119,6 +119,7 @@ "/proc/timer_list", "/proc/timer_stats", "/proc/sched_debug", + "/proc/scsi", }, ReadonlyPaths: []string{ "/proc/asound",