Thread (5 messages) 5 messages, 3 authors, 2015-03-04

Re: [PATCH 2/2] user_namespaces.7: Update the documention to reflect the fixes for negative groups

From: Alban Crequy <hidden>
Date: 2015-02-02 21:31:17
Also in: linux-api, lkml, stable

Possibly related (same subject, not in this thread)

Hello,

Thanks for updating the man page.

On 12 December 2014 at 22:54, Eric W. Biederman [off-list ref] wrote:
(...)
Furthermore to preserve in some form the useful applications that have
been setting gid_map without privilege the file /proc/[pid]/setgroups
was added to allow disabling setgroups.  With the setgroups system
call permanently disabled in a user namespace it again becomes safe to
allow writes to gid_map without privilege.

Here is my meager attempt to update user_namespaces.7 to reflect these
issues.
The program userns_child_exec.c in user_namespaces.7 should be updated
to write in /proc/.../setgroups, near the line:
/* Update the UID and GID maps in the child */

Otherwise, the example given in the manpage does not work:
$ ./userns_child_exec -p -m -U -M '0 1000 1' -G '0 1000 1' bash

Cheers,
Alban
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help