Merge pull request #3377 from nextcloud/enh/noid/drop-net-raw

This commit is contained in:
Simon L 2023-09-27 13:06:38 +02:00 committed by GitHub
commit 8e4678fe82
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -476,6 +476,9 @@ class DockerActionManager
$requestBody['HostConfig']['CapAdd'] = $capAdds;
}
// Disable arp spoofing
$requestBody['HostConfig']['CapDrop'] = ['NET_RAW'];
if ($container->isApparmorUnconfined()) {
$requestBody['HostConfig']['SecurityOpt'] = ["apparmor:unconfined"];
}