Thread (1 message) 1 message, 1 author, 2013-01-07

Re: [PATCH 4/4] setns.2: Document the pid, user, and mount namespace support.

From: Eric W. Biederman <hidden>
Date: 2013-01-07 23:58:46

"Michael Kerrisk (man-pages)" [off-list ref] writes:
Okay. See below.

So, let's take one more pass. How does the following look:

       A multi-threaded process may not  change  user  namespace  with
       setns().   It  is  not  permitted to use setns() to reenter the
       caller's current user namespace.  This prevents a  caller  that
       has  dropped capabilities from regaining those capabilities via
       a call to setns() A process reassociating itself  with  a  user
       namespace must have CAP_SYS_ADMIN privileges in the target user
       namespace.

       A process may not be reassociated with a new mount namespace if
       it  is  multi-threaded.   Changing the mount namespace requires
       that the caller possess both CAP_SYS_CHROOT  and  CAP_SYS_ADMIN
       capabilities in its own user namespace and CAP_SYS_ADMIN in the
       target mount namespace.
That wording looks correct.

Eric
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help