[Blueprint servercloud-p-lxc-sandboxing] Sandboxing for containers

Jamie Strandboge jamie at ubuntu.com
Wed Nov 23 19:49:23 UTC 2011


Blueprint changed by Jamie Strandboge:

Whiteboard changed:
  Status: not yet started
  The new candidate seccomp2 patch refuses execve, and is therefore not compatible with LXC.  A general sandbox tool is still possible, and seccomp2 may later be extended to be usable with LXC.
  
  Work Items:
- [jjohansen] Get seccomp2 into ubuntu kernel or ppa for testing: INPROGRESS
+ [jjohansen] Get seccomp2 into ubuntu kernel or ppa for testing: DONE
  [serge-hallyn] Work with jjohansen/kees/upstream to design generic sandbox program: TODO
  [serge-hallyn] Propose design for lxc integration to lxc-dev: TODO
  [serge-hallyn] Implement prototype of lxc seccomp2 integration: TODO
  [serge-hallyn] Write testcases for lxc seccomp2 integration: TODO

-- 
Sandboxing for containers
https://blueprints.launchpad.net/ubuntu/+spec/servercloud-p-lxc-sandboxing



More information about the Ubuntu-server-bugs mailing list