Open bnoordhuis opened 3 years ago
gVisor currently doesn't support ambient capabilities so we'd likely need to support them before supporting PR_CAP_AMBIENT
https://github.com/google/gvisor/issues/3166
A friendly reminder that this issue had no activity for 120 days.
This issue has been closed due to lack of activity.
A friendly reminder that this issue had no activity for 120 days.
Description
We have code to drop ambient capabilities that looks like this:
Works great everywhere except under gVisor, where the prctls fail with EINVAL.
Environment
Whatever version of gVisor GCP's Cloud Run uses. A quick skim of the master branch suggests they're not supported there, either.