|
|
Subscribe / Log in / New account

Namespaced file capabilities

Namespaced file capabilities

[Kernel] Posted Jun 30, 2017 19:50 UTC (Fri) by corbet

The kernel's file capabilities mechanism is a bit of an awkward fit with user namespaces, in that all namespaces have the same view of the capabilities associated with a given executable file. There is a patch set under consideration that adds awareness of user namespaces to file capabilities, but it has brought forth some disagreement on how such a mechanism should work. The question is, in brief: how should a set of file capabilities be picked for any given user namespace?

Full Story (comments: 10)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds