-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add support for container kernel capabilities #716
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Please change flags to |
This patch adds two new command-line flags to specify one or more kernel capabilities to add or remove from the workflow containers. The command-line flag `--container-cap-add` allows for adding specific capabilities on the workflow containers; where as, The command-line flag `--container-cap-drop` allows for removing specific capabilities on the workflow containers. This was developed to specifically be able to add `SYS_PTRACE` to a workflow I maintain. It involves using this capability to monitor a make build, to then build a compilation database. Signed-off-by: Joseph Benden <joe@benden.us>
Codecov Report
@@ Coverage Diff @@
## master #716 +/- ##
==========================================
+ Coverage 49.27% 50.45% +1.18%
==========================================
Files 23 23
Lines 2401 2537 +136
==========================================
+ Hits 1183 1280 +97
- Misses 1090 1116 +26
- Partials 128 141 +13
Continue to review full report at Codecov.
|
catthehacker
approved these changes
Jun 3, 2021
cplee
approved these changes
Jun 4, 2021
catthehacker
pushed a commit
to catthehacker/act-fork
that referenced
this pull request
Nov 14, 2021
Adds option to rebuild local action docker images which is enabled by default Fixed up README due to missing flags after PR nektos#714 and nektos#716 Signed-off-by: hackercat <me@hackerc.at>
catthehacker
pushed a commit
to catthehacker/act-fork
that referenced
this pull request
Nov 22, 2021
Adds option to rebuild local action docker images which is enabled by default Fixed up README due to missing flags after PR nektos#714 and nektos#716 Signed-off-by: hackercat <me@hackerc.at>
catthehacker
pushed a commit
to catthehacker/act-fork
that referenced
this pull request
Nov 22, 2021
Adds option to rebuild local action docker images Fixed up README due to missing flags after PR nektos#714 and nektos#716 Signed-off-by: hackercat <me@hackerc.at>
cplee
pushed a commit
that referenced
this pull request
Nov 24, 2021
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This patch adds two new command-line flags to specify one or
more kernel capabilities to add or remove from the workflow
containers.
The command-line flag
--cap-add
allows for newcapabilities on the workflow containers; where as,
The command-line flag
--cap-drop
allows for removingspecific capabilities on the workflow containers.
This was developed to specifically be able to add
SYS_PTRACE
to a workflow I maintain. It involves using this capability to
monitor a make build, to then build a compilation database.
Signed-off-by: Joseph Benden joe@benden.us