[Lxc-users] Mitigating LXC Container Evasion?

Andre Nathan andre at digirati.com.br
Wed Aug 3 23:05:01 UTC 2011


Hi Mike

On Wed, 2011-08-03 at 17:52 -0400, Michael H. Warfield wrote:
> That's v4 syntax.  Does it not work at all?  Did you try this:
> 
> echo ::/0 @ > /smack/netlabel
> 
> Not having tried this myself at all, I'm just asking.  If it doesn't
> work, that needs to be fixed but it's a SMACK bug.

Olivier's IPv4 example works fine, but with IPv6 I get an error:

# echo ::/0 @ > /smack/netlabel
-bash: echo: write error: Invalid argument

Thanks,
Andre





More information about the lxc-users mailing list