hhvm / packaging

The sources for how we have built the HHVM packages.
MIT License
65 stars 65 forks source link

Add SYS_PTRACE capability to the snapshot container for debugging #277

Closed Atry closed 2 years ago

Atry commented 2 years ago

Make the capability default, because the snapshot container is supposed to be used for debugging purpose.

fredemmott commented 2 years ago

As well as the intent: we're not getting actual security benefits from this given we allow users to exit the container