This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Testing on hosts with firewalls


On 12/30/2016 10:28 AM, Andreas Schwab wrote:
On Dez 29 2016, Mike Frysinger <vapier@gentoo.org> wrote:

$ unshare -Urn

unshare: write failed /proc/self/gid_map: Operation not permitted

There would have to be fallback code for older/restricted kernels. Some distributions disable user namespaces in various ways because they have been shown to expand the kernel attack surface significantly.

If this is a current upstream kernel with user namespaces enabled, I would be worried, though.

Florian


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]