Posted Apr 14, 2012 19:25 UTC (Sat) by BenHutchings (subscriber, #37955)
[Link]
Not completely. fakeroot also fakes up mknod(), and we don't have namespaces for device numbers. But perhaps mknod() could be considered unprivileged on a filesystem mounted -o nodev?
A new approach to user namespaces
Posted Apr 17, 2012 7:36 UTC (Tue) by trulyexcitingnickname-dontuthink (guest, #84181)
[Link]
> But perhaps mknod() could be considered unprivileged on a filesystem mounted -o nodev?
This sounds like a nightmare. Using a more secure mount option make going back to the default insecure? That is sure sane---not.