Re: [patch 07/10] unprivileged mounts: add sysctl tunable for "safe" property

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Miklos Szeredi <miklos@...>
Cc: <akpm@...>, <hch@...>, <serue@...>, <linux-fsdevel@...>, <linux-kernel@...>
Date: Wednesday, February 6, 2008 - 4:21 pm

Quoting Miklos Szeredi (miklos@szeredi.hu):

Thanks, Miklos, good explanations in the docs.

Acked-by: Serge Hallyn <serue@us.ibm.com>

One comment inline, but not imo your problem :)


Yikes, this could be a problem for containers, as it's simply tied to
uid 0, whereas tying it to a capability would let us solve it with
capability bounds.

This might mean more urgency to get user namespaces working at least
with sysfs, else this is a quick way around having CAP_SYS_ADMIN taken
out of a container's capability bounding set.

-
To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [patch 07/10] unprivileged mounts: add sysctl tunable fo..., Serge E. Hallyn, (Wed Feb 6, 4:21 pm)