Re: [Lxc-users] What are the security implications of lxc.cgroup.devices.allow = [cb] *:* m?

2011-02-13 Thread Serge E. Hallyn
Quoting Trent W. Buck (trentb...@gmail.com): I have a container that autobuilds packages (debs with pbuilder, live CDs with live-build). These scripts use chroots, and want to populate (but not use) a bunch of device files within the chroot's /dev. I found that to make this work, I need to

[Lxc-users] What are the security implications of lxc.cgroup.devices.allow = [cb] *:* m?

2011-02-12 Thread Trent W. Buck
I have a container that autobuilds packages (debs with pbuilder, live CDs with live-build). These scripts use chroots, and want to populate (but not use) a bunch of device files within the chroot's /dev. I found that to make this work, I need to 1) remove lxc.cap.drop = mknod 2) add