procd: jail: clean up capability handling and non-root ubusd
authorDaniel Golle <daniel@makrotopia.org>
Mon, 19 Oct 2020 20:39:17 +0000 (21:39 +0100)
committerDaniel Golle <daniel@makrotopia.org>
Wed, 21 Oct 2020 14:22:30 +0000 (15:22 +0100)
commita2def3663a0feff12550906c33f9ecc3e5fb2a5d
treee31c883f642904bd41df5d3bd2eacf96643a59d9
parent2dffadece9a7243a236ce7d91719787a671e23d4
procd: jail: clean up capability handling and non-root ubusd

Unify capability handling to only use OCI spec parsers even for ujail
slim containers which previously supposedly used their own format.

 80c9516 cgroups: restrict allowed keys in 'unified' section
 5ade567 cgroups: memory controller fixes
 3121467 early: run ubusd non-root as user ubus, group ubus
 12a5b97 jail: adapt to new ubus socket path
 788d144 instance: actually wire up capabilities filename
 ebc5a7f jail: nuke old capabilities code in favour of reusing OCI code
 6c5233a jail: capabilities: apply in two phases

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
package/system/procd/Makefile