Releases: google/nsjail
Releases · google/nsjail
nsjail 1.6
- CAP_AUDIT_READ fixes (not present in older kernel headers)
- Fixed dockerfile
nsjail 1.5
- New config examples (e.g. Apache httpd)
- Capability adding
--cap - Improved R/O remounting (missing MS_BIND flag)
- Setting maximum number of used CPUs
--max_cpus - Accept IPv4 in
--bindhost - Use open()/fdopendir() instead of opendir() to set O_CLOEXEC atomically
- Improved docker build file
nsjail 1.4
- --config option using protobuf config files
- config examples in configs/
- removed --pivot_root_only as the technique is used by default now
- flag ToStr() for clone and mount
- updated kafel/ references
- disabled TCP_CORK for incoming connections
- changed --iface to --macvlan_iface & deprecraed --iface* options
nsjail 1.3
Multiple improvements
nsjail 1.2
Improvements
nsjail 1.1
Multiple improvements, virtual interfaces, support for -u <inside_ns>:<global_ns> uid/gid mappings (requires euid==0)
nsjail 1.0
Initial release 1.0