Comment 4 for bug 1729357

Revision history for this message
Serge Hallyn (serge-hallyn) wrote : Re: [Bug 1729357] Re: unprivileged user can drop supplementary groups

@stgraber,

Still trying to wrap my head around whether this currently actually
works. Can you verify that you can use setgroups=deny with a negative
acl in the initial user_ns to prevent a user doing the equivalent of
lxc-usernsexec -m b:0:$(id -u):1 to get around the acl?