[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAKdAkRQj=bSSL2Cw3gAqi5f12yP3+KsvtrMvU4Lcfta_JYxMYQ@mail.gmail.com>
Date: Thu, 28 Feb 2019 11:27:38 -0800
From: Dmitry Torokhov <dmitry.torokhov@...il.com>
To: "Eric W. Biederman" <ebiederm@...ssion.com>
Cc: lkml <linux-kernel@...r.kernel.org>,
"Serge E. Hallyn" <serge@...lyn.com>
Subject: Allowing mapping supplemental groups in user namespace?
Hi Eric,
Currently, unless caller has CAP_SETGID in parent namespace, we can
only map effective group id in the new user namespace. Would it be
possible to relax this rule to also allow mapping of supplemental
groups (1:1) of the caller?
Thanks.
--
Dmitry
Powered by blists - more mailing lists