diff options
Diffstat (limited to 'cmd')
-rw-r--r-- | cmd/podman/create.go | 4 | ||||
-rw-r--r-- | cmd/podman/spec.go | 3 |
2 files changed, 4 insertions, 3 deletions
diff --git a/cmd/podman/create.go b/cmd/podman/create.go index 810a5e3ed..46429b335 100644 --- a/cmd/podman/create.go +++ b/cmd/podman/create.go @@ -128,7 +128,7 @@ type createConfig struct { WorkDir string //workdir MountLabel string //SecurityOpts ProcessLabel string //SecurityOpts - NoNewPrivileges bool //SecurityOpts + NoNewPrivs bool //SecurityOpts ApparmorProfile string //SecurityOpts SeccompProfilePath string //SecurityOpts SecurityOpts []string @@ -252,7 +252,7 @@ func parseSecurityOpt(config *createConfig, securityOpts []string) error { for _, opt := range securityOpts { if opt == "no-new-privileges" { - config.NoNewPrivileges = true + config.NoNewPrivs = true } else { con := strings.SplitN(opt, "=", 2) if len(con) != 2 { diff --git a/cmd/podman/spec.go b/cmd/podman/spec.go index 2c2005399..d535383ba 100644 --- a/cmd/podman/spec.go +++ b/cmd/podman/spec.go @@ -259,7 +259,7 @@ func createConfigToOCISpec(config *createConfig) (*spec.Spec, error) { } // SECURITY OPTS - g.SetProcessNoNewPrivileges(config.NoNewPrivileges) + g.SetProcessNoNewPrivileges(config.NoNewPrivs) g.SetProcessApparmorProfile(config.ApparmorProfile) g.SetProcessSelinuxLabel(config.ProcessLabel) g.SetLinuxMountLabel(config.MountLabel) @@ -665,6 +665,7 @@ func (c *createConfig) GetContainerCreateOptions() ([]libpod.CtrCreateOption, er } options = append(options, libpod.WithPrivileged(c.Privileged)) + options = append(options, libpod.WithNoNewPrivs(c.NoNewPrivs)) return options, nil } |