From 2d4bad680e1fd46d4ee51c4c6aaa67f7f35b10b2 Mon Sep 17 00:00:00 2001 From: deeplow Date: Wed, 10 Aug 2022 19:44:09 +0100 Subject: [PATCH] drop all linux kernel capabilities from containers These are not needed in order to convert documents in the dangerzone containers. --- dangerzone/container.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/dangerzone/container.py b/dangerzone/container.py index 7323fc1..4a67857 100644 --- a/dangerzone/container.py +++ b/dangerzone/container.py @@ -82,6 +82,8 @@ def convert(input_filename, output_filename, ocr_lang, stdout_callback): platform_args = [] security_args = ["--security-opt", "no-new-privileges"] + # drop all linux kernel capabilities + security_args += ["--cap-drop", "all"] # Convert document to pixels