virtcontainers: improve security and mount the rootfs as read-only fs

Mounting the rootfs as read-only fs the binaries can't be modified.

fixes #1389

Signed-off-by: Julio Montes <julio.montes@intel.com>
This commit is contained in:
Julio Montes 2019-03-19 16:42:18 -06:00
parent 8e72cf15e6
commit 64984667ad

View File

@ -32,7 +32,7 @@ var qemuPaths = map[string]string{
var kernelRootParams = []Param{
{"root", "/dev/pmem0p1"},
{"rootflags", "dax,data=ordered,errors=remount-ro rw"},
{"rootflags", "dax,data=ordered,errors=remount-ro ro"},
{"rootfstype", "ext4"},
}