nvidia-container-toolkit/vendor
Evan Lezar ac9146832b
Run update-ldcache in isolated namespaces
This change uses the reexec package to run the update of the
ldcache in a container in a process with isolated namespaces.
Since the hook is invoked as a createContainer hook, these
namespaces are cloned from the container's namespaces.

In the reexec handler, we further isolate the proc filesystem,
mount the host ldconfig to a tmpfs, and pivot into the containers
root.

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2025-05-15 12:51:13 +02:00
..
github.com Run update-ldcache in isolated namespaces 2025-05-15 12:51:13 +02:00
golang.org/x Use libcontainer execseal to run ldconfig 2025-02-28 14:47:31 +02:00
gopkg.in Update CDI package 2023-01-19 12:12:54 +01:00
sigs.k8s.io/yaml Update CDI dependency to v0.5.2 2022-09-29 12:11:41 +02:00
tags.cncf.io/container-device-interface Bump tags.cncf.io/container-device-interface from 0.8.0 to 0.8.1 2025-03-02 08:50:42 +00:00
modules.txt Run update-ldcache in isolated namespaces 2025-05-15 12:51:13 +02:00