On Fri, Feb 17, 2017 at 12:44 AM, Aleksa Sarai [off-list ref] wrote:
quoted
quoted
One thing overlooked by commit 9cc46516ddf4 ("userns: Add a knob to
disable setgroups on a per user namespace basis") is that because
setgroups(2) no longer works in user namespaces it doesn't make any
sense to be returning weird group IDs that the process cannot do
anything with.
bool DropPrivileges()
{
/* ... */
// Verify that the user isn't still in any supplementary groups
But the user *is* still in a supplementary group. Your proposed
change would break the intent of this code.