[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <m11urgidln.fsf@fess.ebiederm.org>
Date: Tue, 03 Jan 2012 15:13:40 -0800
From: ebiederm@...ssion.com (Eric W. Biederman)
To: Steve Grubb <sgrubb@...hat.com>
Cc: Colin Walters <walters@...bum.org>,
"Serge E. Hallyn" <serge@...lyn.com>,
LKML <linux-kernel@...r.kernel.org>, alan@...rguk.ukuu.org.uk,
morgan@...nel.org, luto@....edu, kzak@...hat.com
Subject: Re: chroot(2) and bind mounts as non-root
Steve Grubb <sgrubb@...hat.com> writes:
> On Friday, December 16, 2011 01:14:36 AM Eric W. Biederman wrote:
>> Since except at the edges of userspace we use uids and gids in the
>> initial user namespace, the implications for confusing other security
>> mechanisms is minimized.
>
> Is anyone thinking about how this affects the audit system?
A little.
Today the audit system can only be used from the initial namespaces and
the pids that we use are from the initial pid namespace.
It is my expectation that we can continue the same pattern for uids as
well.
Eric
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists