runc/patch/0014-runc-add-sysctl-kernel.pid_max-to-whitelist.patch
2023-07-28 09:46:10 +08:00

25 lines
782 B
Diff

From 318779ab775bfe878cac0636c9e610b9951e1335 Mon Sep 17 00:00:00 2001
From: zhongjiawei <zhongjiawei1@huawei.com>
Date: Tue, 25 Jul 2023 19:53:00 +0800
Subject: [PATCH] runc:add sysctl kernel.pid_max to whitelist
---
libcontainer/configs/validate/validator.go | 1 +
1 file changed, 1 insertion(+)
diff --git a/libcontainer/configs/validate/validator.go b/libcontainer/configs/validate/validator.go
index 4fbd308..5ef0e8d 100644
--- a/libcontainer/configs/validate/validator.go
+++ b/libcontainer/configs/validate/validator.go
@@ -170,6 +170,7 @@ func (v *ConfigValidator) sysctl(config *configs.Config) error {
"kernel.shmmax": true,
"kernel.shmmni": true,
"kernel.shm_rmid_forced": true,
+ "kernel.pid_max": true,
}
var (
--
2.33.0