Re: [PATCH 2/2] user namespaces: require cap_set{ug}id for CLONE_NEWUSER

From: Eric W. Biederman
Date: Fri Dec 05 2008 - 12:26:36 EST


"Serge E. Hallyn" <serue@xxxxxxxxxx> writes:

>> Personally the user namespace only becomes interesting when we
>> start to be able to move in the other direction and remove the
>> set of capabilities requires to create it.
>>
>> Eric
>
> Agreed. Now the thing is I don't think we need full userns
> support to get there. We just need the targeted capabilities
> and the basic dummy fs support - that is, init_user_ns owns
> all vfsmounts, and anyone not in init_user_ns only gets
> user other access to files under those mounts.

Right.

> Of course complete support for targeted caps will in itself
> be a huge effort :)
>
> So my roadmap is: next address the per-user keyring, then
> the targeted caps.

Sounds good.

I expect this means we will pass through a period where the user
namespace is less useful than it is today. But as it will be on
a much firmer foundation that is fine.

Eric

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/