A container that can reach host devices escapes through them. A privileged container sees every device; a specific --device grant or CAP_MKNOD exposes one. The two that matter most are the host's root block device (mount it, own the filesystem) and kernel or physical memory (patch the running kernel).
ls -l /dev # what devices are visible
cat /proc/partitions # host block devices, e.g. sda
Subtopics#
- Host block device: mount the host disk directly.
- Kernel memory devices: read and write memory through /dev/mem.
- mknod: create a device node to reach a host device.