Re: [libvirt] [PATCHv3 1/3] lxc: allow to keep or drop capabilities

2014-06-26 Thread Daniel P. Berrange
On Thu, Jun 26, 2014 at 10:40:27AM +0200, Cédric Bosdonnat wrote: > Added in the section of LXC domains > configuration. This section can contain elements named after the > capabilities like: > > , keep CAP_MKNOD capability >drop CAP_SYS_CHROOT capability > > Users can restrict or give mo

[libvirt] [PATCHv3 1/3] lxc: allow to keep or drop capabilities

2014-06-26 Thread Cédric Bosdonnat
Added in the section of LXC domains configuration. This section can contain elements named after the capabilities like: , keep CAP_MKNOD capability drop CAP_SYS_CHROOT capability Users can restrict or give more capabilities than the default using this mechanism. --- docs/schemas/domaincom