You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

38 lines
1.0 KiB

  1. --- a/config/templates/common.conf.in
  2. +++ b/config/templates/common.conf.in
  3. @@ -15,35 +15,6 @@ lxc.cap.drop = mac_admin mac_override sy
  4. # Ensure hostname is changed on clone
  5. lxc.hook.clone = @LXCHOOKDIR@/clonehostname
  6. -# Default legacy cgroup configuration
  7. -#
  8. -# CGroup allowlist
  9. -lxc.cgroup.devices.deny = a
  10. -## Allow any mknod (but not reading/writing the node)
  11. -lxc.cgroup.devices.allow = c *:* m
  12. -lxc.cgroup.devices.allow = b *:* m
  13. -## Allow specific devices
  14. -### /dev/null
  15. -lxc.cgroup.devices.allow = c 1:3 rwm
  16. -### /dev/zero
  17. -lxc.cgroup.devices.allow = c 1:5 rwm
  18. -### /dev/full
  19. -lxc.cgroup.devices.allow = c 1:7 rwm
  20. -### /dev/tty
  21. -lxc.cgroup.devices.allow = c 5:0 rwm
  22. -### /dev/console
  23. -lxc.cgroup.devices.allow = c 5:1 rwm
  24. -### /dev/ptmx
  25. -lxc.cgroup.devices.allow = c 5:2 rwm
  26. -### /dev/random
  27. -lxc.cgroup.devices.allow = c 1:8 rwm
  28. -### /dev/urandom
  29. -lxc.cgroup.devices.allow = c 1:9 rwm
  30. -### /dev/pts/*
  31. -lxc.cgroup.devices.allow = c 136:* rwm
  32. -### fuse
  33. -lxc.cgroup.devices.allow = c 10:229 rwm
  34. -
  35. # Default unified cgroup configuration
  36. #
  37. # CGroup allowlist