diff --git a/daemon/execdriver/native/create.go b/daemon/execdriver/native/create.go index da64c7401..d76dbd258 100644 --- a/daemon/execdriver/native/create.go +++ b/daemon/execdriver/native/create.go @@ -65,7 +65,13 @@ func (d *Driver) createContainer(ctx context.Context, c *execdriver.Command, hoo return nil, err } } - + // add CAP_ prefix to all caps for new libcontainer update to match + // the spec format. + for i, s := range container.Capabilities { + if !strings.HasPrefix(s, "CAP_") { + container.Capabilities[i] = fmt.Sprintf("CAP_%s", s) + } + } container.AdditionalGroups = c.GroupAdd if c.AppArmorProfile != "" { diff --git a/daemon/execdriver/native/exec.go b/daemon/execdriver/native/exec.go index 8327cc765..ac6c13fb2 100644 --- a/daemon/execdriver/native/exec.go +++ b/daemon/execdriver/native/exec.go @@ -6,6 +6,7 @@ import ( "fmt" "os" "os/exec" + "strings" "syscall" "github.com/docker/docker/context" @@ -36,6 +37,13 @@ func (d *Driver) Exec(ctx context.Context, c *execdriver.Command, processConfig if processConfig.Privileged { p.Capabilities = execdriver.GetAllCapabilities() } + // add CAP_ prefix to all caps for new libcontainer update to match + // the spec format. + for i, s := range p.Capabilities { + if !strings.HasPrefix(s, "CAP_") { + p.Capabilities[i] = fmt.Sprintf("CAP_%s", s) + } + } config := active.Config() if err := setupPipes(&config, processConfig, p, pipes); err != nil { diff --git a/daemon/execdriver/utils.go b/daemon/execdriver/utils.go index 6712dafd6..7860e0402 100644 --- a/daemon/execdriver/utils.go +++ b/daemon/execdriver/utils.go @@ -119,6 +119,5 @@ func TweakCapabilities(basics, adds, drops []string) ([]string, error) { newCaps = append(newCaps, strings.ToUpper(cap)) } } - return newCaps, nil }