mirror of
https://github.com/ansible/awx.git
synced 2026-03-27 05:45:02 -02:30
Merge pull request #3875 from wenottingham/pids-in-namespaaaaaaaaace
Unshare PID namespace when using bubblewrap.
This commit is contained in:
@@ -557,7 +557,7 @@ def wrap_args_with_proot(args, cwd, **kwargs):
|
|||||||
- /tmp (except for own tmp files)
|
- /tmp (except for own tmp files)
|
||||||
'''
|
'''
|
||||||
from django.conf import settings
|
from django.conf import settings
|
||||||
new_args = [getattr(settings, 'AWX_PROOT_CMD', 'bwrap'), '--dev-bind', '/', '/']
|
new_args = [getattr(settings, 'AWX_PROOT_CMD', 'bwrap'), '--unshare-pid', '--dev-bind', '/', '/']
|
||||||
hide_paths = ['/etc/tower', '/var/lib/awx', '/var/log',
|
hide_paths = ['/etc/tower', '/var/lib/awx', '/var/log',
|
||||||
tempfile.gettempdir(), settings.PROJECTS_ROOT,
|
tempfile.gettempdir(), settings.PROJECTS_ROOT,
|
||||||
settings.JOBOUTPUT_ROOT]
|
settings.JOBOUTPUT_ROOT]
|
||||||
|
|||||||
Reference in New Issue
Block a user