Unprivileged chroot()
Unprivileged chroot()
Posted Mar 18, 2021 9:14 UTC (Thu) by matthias (subscriber, #94967)In reply to: Unprivileged chroot() by geofft
Parent article: Unprivileged chroot()
Posted Mar 18, 2021 12:26 UTC (Thu)
by winstonx86 (subscriber, #138536)
[Link]
Posted Mar 18, 2021 16:54 UTC (Thu)
by floppus (guest, #137245)
[Link] (1 responses)
For that reason (I think), unprivileged processes can't create user namespaces when they're already chrooted, and the proposed unprivileged chroot would likewise be forbidden.
Posted Mar 18, 2021 17:05 UTC (Thu)
by matthias (subscriber, #94967)
[Link]
And of course, if someone chroots a process without NO_NEW_PRIVS in a classic way, there should be no enchanted chroot command that gets capabilities from the filesystem laying around inside the new root.
Unprivileged chroot()
Unprivileged chroot()
Unprivileged chroot()