Merge pull request #3377 from nextcloud/enh/noid/drop-net-raw

This commit is contained in:
Simon L
2023-09-27 13:06:38 +02:00
committed by GitHub

View File

@@ -476,6 +476,9 @@ class DockerActionManager
$requestBody['HostConfig']['CapAdd'] = $capAdds;
}
// Disable arp spoofing
$requestBody['HostConfig']['CapDrop'] = ['NET_RAW'];
if ($container->isApparmorUnconfined()) {
$requestBody['HostConfig']['SecurityOpt'] = ["apparmor:unconfined"];
}