LWN.net Logo

Namespaces in operation - root privileges

Namespaces in operation - root privileges

Posted Jan 8, 2013 8:53 UTC (Tue) by error27 (subscriber, #8346)
In reply to: Namespaces in operation - root privileges by giraffedata
Parent article: Namespaces in operation, part 1: namespaces overview

These days there root doesn't have all capabilities because of, for example, se-linux. We're sort of working to a goal where people can't load non-vendor modules or firmware without reconfiguring secure boot in the UEFI firmware. So there are all kinds of things which root will be restricted from doing by default.

One use of new namespace work would be to set up a chroot where people could install mysql and set up a webserver etc. It's cheaper than using KVM for virtualization.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds