nvidia-container-toolkit/vendor
Evan Lezar ac9146832b
Run update-ldcache in isolated namespaces
This change uses the reexec package to run the update of the
ldcache in a container in a process with isolated namespaces.
Since the hook is invoked as a createContainer hook, these
namespaces are cloned from the container's namespaces.

In the reexec handler, we further isolate the proc filesystem,
mount the host ldconfig to a tmpfs, and pivot into the containers
root.

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2025-05-15 12:51:13 +02:00
..
github.com Run update-ldcache in isolated namespaces 2025-05-15 12:51:13 +02:00
golang.org/x Use libcontainer execseal to run ldconfig 2025-02-28 14:47:31 +02:00
gopkg.in
sigs.k8s.io/yaml
tags.cncf.io/container-device-interface Bump tags.cncf.io/container-device-interface from 0.8.0 to 0.8.1 2025-03-02 08:50:42 +00:00
modules.txt Run update-ldcache in isolated namespaces 2025-05-15 12:51:13 +02:00