mirror of
https://github.com/NVIDIA/nvidia-container-toolkit
synced 2025-06-03 11:27:17 +00:00
This change uses the reexec package to run the update of the ldcache in a container in a process with isolated namespaces. Since the hook is invoked as a createContainer hook, these namespaces are cloned from the container's namespaces. In the reexec handler, we further isolate the proc filesystem, mount the host ldconfig to a tmpfs, and pivot into the containers root. Signed-off-by: Evan Lezar <elezar@nvidia.com> |
||
---|---|---|
.. | ||
github.com | ||
golang.org/x | ||
gopkg.in/yaml.v3 | ||
sigs.k8s.io/yaml | ||
tags.cncf.io/container-device-interface | ||
modules.txt |