Comment 1 for bug 1202839

Revision history for this message
Serge Hallyn (serge-hallyn) wrote :

Note that in quantal that file is shipped without CAP_NET_ADMIN and not suid-root. Therefore it was useless to its intended purpose there.

The point of that file is to allow unprivileged users to create tap devices for their VMs. You can create tap devices yourself for that purpose easily, or use libvirt to do it for you.

Shipping this file and a bridge.conf configuration file isn't out of the question, but would need to be vetted by the security team.