summaryrefslogtreecommitdiffstats
path: root/fs/namespace.c
diff options
context:
space:
mode:
authorEric W. Biederman2012-07-31 10:14:12 +0200
committerEric W. Biederman2012-11-19 14:59:17 +0100
commita85fb273c94648cbf20a5f9bcf8bbbb075f271ad (patch)
treebdfe3d662dd4a42673620067f21c7b6fedd04d27 /fs/namespace.c
parentpidns: Support unsharing the pid namespace. (diff)
downloadkernel-qcow2-linux-a85fb273c94648cbf20a5f9bcf8bbbb075f271ad.tar.gz
kernel-qcow2-linux-a85fb273c94648cbf20a5f9bcf8bbbb075f271ad.tar.xz
kernel-qcow2-linux-a85fb273c94648cbf20a5f9bcf8bbbb075f271ad.zip
vfs: Allow chroot if you have CAP_SYS_CHROOT in your user namespace
Once you are confined to a user namespace applications can not gain privilege and escape the user namespace so there is no longer a reason to restrict chroot. Acked-by: Serge Hallyn <serge.hallyn@canonical.com> Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Diffstat (limited to 'fs/namespace.c')
0 files changed, 0 insertions, 0 deletions