Cc: Serge E. Hallyn <serue@...>, Ian Kent <raven@...>, Jeff Moyer <jmoyer@...>, Andrew Morton <akpm@...>, Kernel Mailing List <linux-kernel@...>, autofs mailing list <autofs@...>, linux-fsdevel <linux-fsdevel@...>, Eric W. Biederman <ebiederm@...>
For the reasons I listed there :)
You can become root in the new container. Your capabilities are
meaningful only to targets (users, files) which exist in the user
namespace in which you are root. It becomes more precise than the
CAP_NS_OVERRIDE approach in my last patchset.
--