Drop as much capabilities as possibile for the Collabora container (#8000)

This commit is contained in:
Pablo Zmdl
2026-07-18 14:02:17 +02:00
committed by GitHub
4 changed files with 17 additions and 4 deletions
+8 -3
View File
@@ -401,8 +401,11 @@ readonly class DockerActionManager {
$requestBody['HostConfig']['CapAdd'] = $capAdds;
}
// Disable arp spoofing
if (!in_array('NET_RAW', $capAdds, true)) {
$capDrops = $container->capDrop;
if (count($capDrops) > 0) {
$requestBody['HostConfig']['CapDrop'] = $capDrops;
} else if (!in_array('NET_RAW', $capAdds, true)) {
// Prevent ARP spoofing by default
$requestBody['HostConfig']['CapDrop'] = ['NET_RAW'];
}
@@ -463,9 +466,11 @@ readonly class DockerActionManager {
// Special things for the collabora container which should not be exposed in the containers.json
} elseif ($container->identifier === 'nextcloud-aio-collabora') {
if (!$this->configurationManager->collaboraSeccompDisabled) {
// Load reference seccomp profile for collabora
// Load reference seccomp profile for collabora...
$seccompProfile = (string)file_get_contents(DataConst::GetCollaboraSeccompProfilePath());
$requestBody['HostConfig']['SecurityOpt'] = ["label:disable", "seccomp=$seccompProfile"];
// ...which allows the collabora container to run without any capabilities
$requestBody['HostConfig']['CapAdd'] = [];
}
// Additional Collabora options