YuPengZTE
8ae21d6d4d
The etc and dot is seprated
...
Signed-off-by: YuPengZTE <yu.peng36@zte.com.cn >
(cherry picked from commit bd914ff5a3 )
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-09-29 14:24:38 +02:00
Sebastiaan van Stijn
99ed95cb57
Merge pull request #26526 from lixiaobing10051267/masterSymble
...
fix some incorrect symbols before executing command
(cherry picked from commit 9e9ba1e1c1 )
Signed-off-by: Misty Stanley-Jones <misty@docker.com >
2016-09-16 10:03:13 -07:00
Justin Cormack
787ed27c32
Merge pull request #26496 from riyazdf/trust-sandbox-fix
...
Use latest version of notary server in trust sandbox docs
(cherry picked from commit 6fafd07282 )
Signed-off-by: Misty Stanley-Jones <misty@docker.com >
2016-09-16 10:03:12 -07:00
Vincent Demeester
af9378f713
Merge pull request #25996 from yuexiao-wang/fix-docker-daemon
...
Replace docker command from 'docker daemon' to 'dockerd'
(cherry picked from commit aff33055ac )
Signed-off-by: Charles Smith <charles.smith@docker.com >
2016-09-06 11:06:57 -07:00
Sebastiaan van Stijn
0f63ddb03d
Fix capitalization
...
Signed-off-by: YuPengZTE <yu.peng36@zte.com.cn >
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
(cherry picked from commit 75e60fbe09 )
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-08-17 23:22:00 +02:00
Charles Smith
3da4ac64af
add overlay networking security model node
...
Signed-off-by: Charles Smith <charles.smith@docker.com >
(cherry picked from commit cc5debcb2e )
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-08-17 23:21:59 +02:00
Sven Dowideit
8cc5797894
Merge pull request #25569 from friism/fix-typo-in-security-doc
...
update intro to say there are four things to consider
(cherry picked from commit ce2ca236db )
Signed-off-by: Sven Dowideit <SvenDowideit@home.org.au >
(cherry picked from commit 7cee444f8b )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-08-11 16:36:34 -07:00
Sebastiaan van Stijn
fff3dce95f
Merge pull request #25421 from avaid96/patch-1
...
minor nit typo in opensl(openssl) genrsa -out delegation.key 2048
(cherry picked from commit 4191b786c5 )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-08-11 16:32:21 -07:00
Sebastiaan van Stijn
5cad6c1df8
Merge pull request #25318 from lixiaobing10051267/masterParentheses
...
A parenthesis omitted in Seccomp.md
(cherry picked from commit d7c9c85e30 )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-08-11 16:32:17 -07:00
Sebastiaan van Stijn
9c2ba289dd
Merge pull request #25020 from jfrazelle/update-non-events
...
update security non-events
(cherry picked from commit 14664beda9 )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-08-11 16:32:14 -07:00
Tonis Tiigi
2456150a52
Update docker load security docs
...
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com >
(cherry picked from commit f17469e890 )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-07-25 23:15:26 -07:00
Sebastiaan van Stijn
bc5eb28299
Fix some broken sourceforge.net links
...
Looks like there's issues with sourceforge project
pages. Given that sourceforge isn't really what
it used to be, trying to find alternative URLs
where possible.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
(cherry picked from commit 0e7a1079be )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-07-12 15:50:37 -07:00
Mansi Nahar
c164011a4e
Change content-trust doc to not point to images that don't exist #22730
...
Signed-off-by: Mansi Nahar <mmn4185@rit.edu >
(cherry picked from commit 82d70f4409 )
Signed-off-by: Tibor Vass <tibor@docker.com >
2016-07-12 15:43:40 -07:00
cyli
ba115b0a91
Update content trust docs to reflect latest notary compose file changes, and to simplify
...
the instructions by providing a single compose file that runs the notary server, registry,
and a docker-in-docker trust sandbox.
Signed-off-by: cyli <cyli@twistedmatrix.com >
2016-06-13 12:57:06 -07:00
Sebastiaan van Stijn
5b1060c775
Merge pull request #23354 from riyazdf/notary-delegation-env
...
Add link to notary environment vars from docker trust automation section
2016-06-09 00:09:28 +02:00
Riyaz Faizullabhoy
8d72ff3f5e
Add link to notary environment vars from docker trust automation section
...
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com >
2016-06-07 14:03:56 -07:00
allencloud
c1be45fa38
fix typos
...
Signed-off-by: allencloud <allen.sun@daocloud.io >
2016-06-02 17:17:22 +08:00
Alexander Morozov
c95f1fcbd9
Merge pull request #22679 from cyli/bump-notary-version
...
Bump notary version up to 0.3.0 and re-vendor.
2016-05-12 14:38:07 -07:00
Vincent Demeester
475c37dd66
Merge pull request #22694 from allencloud/fix-typos-in-docs
...
docs: correct some typos
2016-05-12 14:35:39 +02:00
Vincent Demeester
edf5e097a2
Merge pull request #22687 from haoshuwei/fix-docs-securitymd
...
Fixing security.md
2016-05-12 14:35:21 +02:00
allencloud
57e2a82355
fix typos in docs
...
Signed-off-by: allencloud <allen.sun@daocloud.io >
2016-05-12 18:38:02 +08:00
Sebastiaan van Stijn
067e54eeac
docs: update menu order in security section
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-05-12 11:19:53 +02:00
Sebastiaan van Stijn
a14e85c40d
Merge pull request #22579 from jfrazelle/docs-add-security-non-events
...
docs: add security non-events
2016-05-12 11:17:47 +02:00
Hao Shu Wei
73d96a6b17
Fixing security.md
...
Signed-off-by: Hao Shu Wei <haoshuwei1989@163.com >
2016-05-12 16:52:03 +08:00
cyli
6094be63ac
Bump notary version up to 0.3.0 and re-vendor.
...
Signed-off-by: cyli <cyli@twistedmatrix.com >
2016-05-11 22:57:51 -07:00
Sebastiaan van Stijn
2cddd1cd1f
docs: update seccomp whitelist
...
the 'modify_ldt' was listed as "blocked by default",
but was whitelisted in 13a9d4e899
this updates the documentation to reflect this
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-05-11 18:45:27 +02:00
Jess Frazelle
6f06e98f57
docs: add security non-events
...
Signed-off-by: Jess Frazelle <jess@mesosphere.com >
Signed-off-by: Jess Frazelle <me@jessfraz.com >
2016-05-09 09:35:19 -07:00
Vincent Demeester
1c1947dd29
Merge pull request #22386 from wenchma/dockerd
...
Update the `docker daemon` to `dockerd` for document
2016-05-04 15:07:53 +02:00
Wen Cheng Ma
24ec73f754
Update the docker daemon to dockerd for document
...
Signed-off-by: Wen Cheng Ma <wenchma@cn.ibm.com >
2016-04-29 09:06:02 +08:00
Antonio Murdaca
09021d6841
Merge pull request #22344 from cpuguy83/seccomp_for_centos
...
centos:7/oraclelinux:7 now includes libseccomp 2.2.1
2016-04-28 12:26:22 +02:00
Riyaz Faizullabhoy
77da3bcb72
Update DCT docs with 1.11 info, fix typos
...
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com >
2016-04-27 09:57:54 -07:00
Brian Goff
1521a41fc5
centos:7/OL:7 now includes libseccomp 2.2.1
...
Signed-off-by: Brian Goff <cpuguy83@gmail.com >
2016-04-26 20:48:26 -04:00
Thomas Grainger
ea8f9c9723
Fix security documentation, XSS -> CSRF
...
Signed-off-by: Thomas Grainger <tagrain@gmail.com >
2016-04-15 11:29:37 +01:00
Jess Frazelle
80d63e2e11
Add example to apparmor docs
...
Signed-off-by: Jess Frazelle <jess@mesosphere.com >
2016-04-14 10:59:47 -07:00
Tibor Vass
3ce494f48c
Merge pull request #21367 from mlaventure/containerd-docs-cleanup
...
Remove unneeded references to execDriver
2016-03-22 19:40:27 -04:00
Kenfe-Mickael Laventure
8af4f89cba
Remove unneeded references to execDriver
...
This includes:
- updating the docs
- removing dangling variables
Signed-off-by: Kenfe-Mickael Laventure <mickael.laventure@gmail.com >
2016-03-21 13:06:08 -07:00
cyli
88d73ebff4
Include documentation on how to add the targets/releases delegation to a repo
...
Signed-off-by: cyli <cyli@twistedmatrix.com >
2016-03-21 12:06:10 -07:00
Jess Frazelle
06e98f0a5c
Merge pull request #21232 from calavera/consolidate_security_opts_format
...
Consolidate security options to use `=` as separator.
2016-03-18 16:02:38 -07:00
Yong Tang
3c6aa163a3
Fix several typos in the documentation.
...
This pull request fixes several typos in the documentation.
Signed-off-by: Yong Tang <yong.tang.github@outlook.com >
2016-03-17 18:29:35 +00:00
David Calavera
cb9aeb0413
Consolidate security options to use = as separator.
...
All other options we have use `=` as separator, labels,
log configurations, graph configurations and so on.
We should be consistent and use `=` for the security
options too.
Signed-off-by: David Calavera <david.calavera@gmail.com >
2016-03-17 13:34:42 -04:00
David Calavera
553ffa7fd7
Merge pull request #21279 from WeiZhang555/typo
...
Fix typo
2016-03-17 08:20:26 -07:00
Zhang Wei
ca64269165
Fix typo
...
Signed-off-by: Zhang Wei <zhangwei555@huawei.com >
2016-03-17 16:13:51 +08:00
Justin Cormack
96896f2d0b
Add new syscalls in libseccomp 2.3.0 to seccomp default profile
...
This adds the following new syscalls that are supported in libseccomp 2.3.0,
including calls added up to kernel 4.5-rc4:
mlock2 - same as mlock but with a flag
copy_file_range - copy file contents, like splice but with reflink support.
The following are not added, and mentioned in docs:
userfaultfd - userspace page fault handling, mainly designed for process migration
The following are not added, only apply to less common architectures:
switch_endian
membarrier
breakpoint
set_tls
I plan to review the other architectures, some of which can now have seccomp
enabled in the build as they are now supported.
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2016-03-16 21:17:32 +00:00
Justin Cormack
5abd881883
Allow restart_syscall in default seccomp profile
...
Fixes #20818
This syscall was blocked as there was some concern that it could be
used to bypass filtering of other syscall arguments. However none of the
potential syscalls where this could be an issue (poll, nanosleep,
clock_nanosleep, futex) are blocked in the default profile anyway.
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2016-03-11 16:44:11 +00:00
Antonio Murdaca
dc0397c9a8
docs: security: seccomp: mention Docker needs seccomp build and check config
...
Signed-off-by: Antonio Murdaca <runcom@redhat.com >
2016-03-03 12:04:09 +01:00
Steven Iveson
244e5fc516
Update seccomp.md
...
Corrected titles to use title case. Added link to default.json and some numerical detail. Changed example JSON to a portion of the actual default file, with the correct defaultAction.
Signed-off-by: Steven Iveson <steven.iveson@infinityworks.com >
2016-02-29 16:32:45 +00:00
Rory McCune
c1e53ad1aa
Update security.md with basic User Namespace info.
...
Just some suggested wording to update this page to take account of User Namespaces being available as of 1.10.
Signed-off-by: Rory McCune <rorym@mccune.org.uk >
2016-02-24 20:53:00 +00:00
Kai Qiang Wu(Kennan)
4d4d1e7f82
Fix doc format issue
...
Signed-off-by: Kai Qiang Wu(Kennan) <wkqwu@cn.ibm.com >
2016-02-23 03:42:10 +00:00
Sebastiaan van Stijn
13839a6d32
Be more explicit on seccomp availability
...
Seccomp is only *compiled* in binaries built for
distros that ship with seccomp 2.2.1 or higher,
and in the static binaries.
The static binaries are not really useful for
RHEL and CentOS, because devicemapper does
not work properly with the static binaries,
so static binaries is only an option for Ubuntu
and Debian.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-02-18 14:57:47 +01:00
Sebastiaan van Stijn
6ab52f9f00
Add note that seccomp 2.2.1 or higher is required
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2016-02-05 21:26:03 +01:00