Re: CLONE_NEWUSER documentation

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Serge E. Hallyn
Date: Monday, August 6, 2007 - 6:09 am

Quoting Eric W. Biederman (ebiederm@xmission.com):

I think the two main omissions are that one, and the fact that there is
no concept of a capability mask or per-namespace/cross-namespace
capabilities.  What is implemented is separate accounting for the same
uid in different namespaces.

Until the shortcomings are addressed, depending on one's use case, one
may want to use selinux to control access across user namespaces.


thanks,
-serge
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
CLONE_NEWUSER documentation, Michael Kerrisk, (Sun Aug 5, 2:35 am)
Re: CLONE_NEWUSER documentation, Eric W. Biederman, (Sun Aug 5, 5:36 am)
Re: CLONE_NEWUSER documentation, Michael Kerrisk, (Sun Aug 5, 11:36 pm)
Re: CLONE_NEWUSER documentation, Eric W. Biederman, (Sun Aug 5, 11:48 pm)
Re: CLONE_NEWUSER documentation, Serge E. Hallyn, (Mon Aug 6, 6:09 am)