From 318779ab775bfe878cac0636c9e610b9951e1335 Mon Sep 17 00:00:00 2001 From: zhongjiawei Date: Tue, 25 Jul 2023 19:53:00 +0800 Subject: [PATCH] runc:add sysctl kernel.pid_max to whitelist --- libcontainer/configs/validate/validator.go | 1 + 1 file changed, 1 insertion(+) diff --git a/libcontainer/configs/validate/validator.go b/libcontainer/configs/validate/validator.go index 4fbd308..5ef0e8d 100644 --- a/libcontainer/configs/validate/validator.go +++ b/libcontainer/configs/validate/validator.go @@ -170,6 +170,7 @@ func (v *ConfigValidator) sysctl(config *configs.Config) error { "kernel.shmmax": true, "kernel.shmmni": true, "kernel.shm_rmid_forced": true, + "kernel.pid_max": true, } var ( -- 2.33.0