mirror of
https://github.com/nextcloud/all-in-one.git
synced 2026-09-19 17:50:20 +00:00
Revert "Drop as much capabilities as possibile for the Collabora container (#8000)"
This reverts commit9dcb25b4ae, reversing changes made to261675f4d3.
This commit is contained in:
@@ -401,11 +401,8 @@ readonly class DockerActionManager {
|
||||
$requestBody['HostConfig']['CapAdd'] = $capAdds;
|
||||
}
|
||||
|
||||
$capDrops = $container->capDrop;
|
||||
if (count($capDrops) > 0) {
|
||||
$requestBody['HostConfig']['CapDrop'] = $capDrops;
|
||||
} else if (!in_array('NET_RAW', $capAdds, true)) {
|
||||
// Prevent ARP spoofing by default
|
||||
// Disable arp spoofing
|
||||
if (!in_array('NET_RAW', $capAdds, true)) {
|
||||
$requestBody['HostConfig']['CapDrop'] = ['NET_RAW'];
|
||||
}
|
||||
|
||||
@@ -466,11 +463,9 @@ readonly class DockerActionManager {
|
||||
// Special things for the collabora container which should not be exposed in the containers.json
|
||||
} elseif ($container->identifier === 'nextcloud-aio-collabora') {
|
||||
if (!$this->configurationManager->collaboraSeccompDisabled) {
|
||||
// Load reference seccomp profile for collabora...
|
||||
// Load reference seccomp profile for collabora
|
||||
$seccompProfile = (string)file_get_contents(DataConst::GetCollaboraSeccompProfilePath());
|
||||
$requestBody['HostConfig']['SecurityOpt'] = ["label:disable", "seccomp=$seccompProfile"];
|
||||
// ...which allows the collabora container to run without any capabilities
|
||||
$requestBody['HostConfig']['CapAdd'] = [];
|
||||
}
|
||||
|
||||
// Additional Collabora options
|
||||
|
||||
Reference in New Issue
Block a user