diff options
Diffstat (limited to 'libpod/container_api.go')
-rw-r--r-- | libpod/container_api.go | 13 |
1 files changed, 7 insertions, 6 deletions
diff --git a/libpod/container_api.go b/libpod/container_api.go index 2dfb166ec..f79be4ac7 100644 --- a/libpod/container_api.go +++ b/libpod/container_api.go @@ -237,12 +237,13 @@ func (c *Container) Exec(tty, privileged bool, env, cmd []string, user string) e log: c.LogPath(), } execOpts := runcExecOptions{ - capAdd: capList, - pidFile: filepath.Join(c.state.RunDir, fmt.Sprintf("%s-execpid", stringid.GenerateNonCryptoID()[:12])), - env: env, - user: user, - cwd: c.config.Spec.Process.Cwd, - tty: tty, + capAdd: capList, + pidFile: filepath.Join(c.state.RunDir, fmt.Sprintf("%s-execpid", stringid.GenerateNonCryptoID()[:12])), + env: env, + noNewPrivs: c.config.NoNewPrivs, + user: user, + cwd: c.config.Spec.Process.Cwd, + tty: tty, } return c.runtime.ociRuntime.execContainer(c, cmd, globalOpts, execOpts) |