| { |
| "ociVersion": "1.0.2-dev", |
| "process": { |
| "terminal": true, |
| "user": { |
| "uid": 0, |
| "gid": 0 |
| }, |
| "args": [ |
| "sh" |
| ], |
| "env": [ |
| "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", |
| "TERM=xterm" |
| ], |
| "cwd": "/", |
| "capabilities": { |
| "bounding": [ |
| "CAP_AUDIT_WRITE", |
| "CAP_KILL", |
| "CAP_NET_BIND_SERVICE" |
| ], |
| "effective": [ |
| "CAP_AUDIT_WRITE", |
| "CAP_KILL", |
| "CAP_NET_BIND_SERVICE" |
| ], |
| "inheritable": [ |
| "CAP_AUDIT_WRITE", |
| "CAP_KILL", |
| "CAP_NET_BIND_SERVICE" |
| ], |
| "permitted": [ |
| "CAP_AUDIT_WRITE", |
| "CAP_KILL", |
| "CAP_NET_BIND_SERVICE" |
| ], |
| "ambient": [ |
| "CAP_AUDIT_WRITE", |
| "CAP_KILL", |
| "CAP_NET_BIND_SERVICE" |
| ] |
| }, |
| "rlimits": [ |
| { |
| "type": "RLIMIT_NOFILE", |
| "hard": 1024, |
| "soft": 1024 |
| } |
| ], |
| "noNewPrivileges": true |
| }, |
| "root": { |
| "path": "/tmp/userns-test/rootfs" |
| }, |
| "hostname": "runc", |
| "mounts": [ |
| { |
| "destination": "/proc", |
| "type": "proc", |
| "source": "proc" |
| }, |
| { |
| "destination": "/dev", |
| "type": "tmpfs", |
| "source": "tmpfs", |
| "options": [ |
| "nosuid", |
| "strictatime", |
| "mode=755", |
| "size=65536k" |
| ] |
| }, |
| { |
| "destination": "/dev/pts", |
| "type": "devpts", |
| "source": "devpts", |
| "options": [ |
| "nosuid", |
| "noexec", |
| "newinstance", |
| "ptmxmode=0666", |
| "mode=0620", |
| "gid=5" |
| ] |
| }, |
| { |
| "destination": "/dev/shm", |
| "type": "tmpfs", |
| "source": "shm", |
| "options": [ |
| "nosuid", |
| "noexec", |
| "nodev", |
| "mode=1777", |
| "size=65536k" |
| ] |
| }, |
| { |
| "destination": "/dev/mqueue", |
| "type": "mqueue", |
| "source": "mqueue", |
| "options": [ |
| "nosuid", |
| "noexec", |
| "nodev" |
| ] |
| }, |
| { |
| "destination": "/sys", |
| "type": "sysfs", |
| "source": "sysfs", |
| "options": [ |
| "nosuid", |
| "noexec", |
| "nodev", |
| "ro" |
| ] |
| }, |
| { |
| "destination": "/sys/fs/cgroup", |
| "type": "cgroup", |
| "source": "cgroup", |
| "options": [ |
| "nosuid", |
| "noexec", |
| "nodev", |
| "relatime", |
| "ro" |
| ] |
| } |
| ], |
| "linux": { |
| "uidMappings": [ |
| { |
| "containerID": 0, |
| "hostID": 65536, |
| "size": 65536 |
| } |
| ], |
| "gidMappings": [ |
| { |
| "containerID": 0, |
| "hostID": 65536, |
| "size": 65536 |
| } |
| ], |
| "resources": { |
| "devices": [ |
| { |
| "allow": false, |
| "access": "rwm" |
| } |
| ] |
| }, |
| "namespaces": [ |
| { |
| "type": "pid" |
| }, |
| { |
| "type": "network" |
| }, |
| { |
| "type": "ipc" |
| }, |
| { |
| "type": "uts" |
| }, |
| { |
| "type": "mount" |
| }, |
| { |
| "type": "cgroup" |
| }, |
| { |
| "type": "user" |
| } |
| ], |
| "maskedPaths": [ |
| "/proc/acpi", |
| "/proc/asound", |
| "/proc/kcore", |
| "/proc/keys", |
| "/proc/latency_stats", |
| "/proc/timer_list", |
| "/proc/timer_stats", |
| "/proc/sched_debug", |
| "/sys/firmware", |
| "/proc/scsi" |
| ], |
| "readonlyPaths": [ |
| "/proc/bus", |
| "/proc/fs", |
| "/proc/irq", |
| "/proc/sys", |
| "/proc/sysrq-trigger" |
| ] |
| } |
| } |