[linux-user-chroot] Created tag v2015.1
- From: Colin Walters <walters src gnome org>
- To: commits-list gnome org
- Cc:
- Subject: [linux-user-chroot] Created tag v2015.1
- Date: Sun, 6 Sep 2015 16:18:00 +0000 (UTC)
The signed tag 'v2015.1' was created.
Tagger: Colin Walters <walters verbum org>
Date: Sun Sep 6 12:17:03 2015 -0400
Release 2015.1
This is the first real feature release in two years. In the
intervening time, there has been a *lot* of interest in Linux
containers. However, there is to my knowledge still not another
project that achieves the same targeted feature set linux-user-chroot
has around *non-root* containers.
There are two new *opt-in* restrictions:
- `--mount-devapi /dev`: Create just the API mount points
- `--seccomp-profile-version 0`: Initial seccomp filtering
This release also drops support for RHEL6 era systems, and seccomp
is a hard requirement.
Git-EVTag-v0-SHA512:
3fb4a7e4c8a75004abd97133cde7bdb69ca9a6622df7601a760083bae43f278d8c266bbaa32e5fa008e806cf1854e0ec89839a1cc86a984e085f8628274bfe4d
Changes since the last tag 'v2013.1':
Colin Walters (16):
Bump up bind mount limit to 1024
README: Various updates
TODO: Want seccomp
Drop use of SECBIT_NOROOT, hard require PR_SET_NO_NEW_PRIVS
Import S390/CRIS raw_clone syscall ordering fix
Add seccomp and rules imported from xdg-app/Sandstorm.io
seccomp: Add ptrace to blacklist
Drop -newnet variant
docs: Update to note we do containers, but are mainly for build systems
README: Update
Add --mount-devapi option
TODO: Update
core: Update comments around PR_SET_NO_NEW_PRIVS and nosuid mount
core: Update comment for private/slave mode of / mount
doc: Add --mount-devapi, some typo fixes
Release 2015.1
[
Date Prev][
Date Next] [
Thread Prev][
Thread Next]
[
Thread Index]
[
Date Index]
[
Author Index]