From: Stéphane Graber Date: Mon, 9 Dec 2013 22:05:26 +0000 (-0500) Subject: ubuntu: Add comment about the mounting profile X-Git-Tag: lxc-1.0.0.beta1~34 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=6472dcc2c944a757f4f373f1cf1fc86b4369feea;p=thirdparty%2Flxc.git ubuntu: Add comment about the mounting profile Signed-off-by: Serge Hallyn Acked-by: Stéphane Graber --- diff --git a/config/templates/ubuntu.common.conf.in b/config/templates/ubuntu.common.conf.in index ef4e818ee..0575321a4 100644 --- a/config/templates/ubuntu.common.conf.in +++ b/config/templates/ubuntu.common.conf.in @@ -27,6 +27,11 @@ lxc.cap.drop = sys_module mac_admin mac_override sys_time #lxc.aa_profile = lxc-container-default-with-nesting #lxc.hook.mount = /usr/share/lxc/hooks/mountcgroups +# If you wish to allow mounting block filesystems, then use the following +# line instead, and make sure to grant access to the block device and/or loop +# devices below in lxc.cgroup.devices.allow. +#lxc.aa_profile = lxc-container-default-with-mounting + # Default cgroup limits lxc.cgroup.devices.deny = a ## Allow any mknod (but not using the node) @@ -56,3 +61,6 @@ lxc.cgroup.devices.allow = c 1:7 rwm lxc.cgroup.devices.allow = c 10:228 rwm ## kvm lxc.cgroup.devices.allow = c 10:232 rwm +## To use loop devices, copy the following line to the container's +## configuration file (uncommented). +#lxc.cgroup.devices.allow = b 7:* rwm