[Devel] Re: [patch 05/10] add "permit user mounts in new namespace" clone flag

Eric W. Biederman ebiederm at xmission.com
Mon Apr 16 08:43:55 PDT 2007


Miklos Szeredi <miklos at szeredi.hu> writes:

> That depends.  Current patches check the "unprivileged submounts
> allowed under this mount" flag only on the requested mount and not on
> the propagated mounts.  Do you see a problem with this?

I think privileges of this sort should propagate.  If I read what you
just said correctly if I have a private mount namespace I won't be able
to mount anything unless when it was setup the unprivileged submount
command was explicitly set.

Eric
_______________________________________________
Containers mailing list
Containers at lists.linux-foundation.org
https://lists.linux-foundation.org/mailman/listinfo/containers




More information about the Devel mailing list