Still trying to wrap my head around whether this currently actually
works. Can you verify that you can use setgroups=deny with a negative
acl in the initial user_ns to prevent a user doing the equivalent of
lxc-usernsexec -m b:0:$(id -u):1 to get around the acl?
@stgraber,
Still trying to wrap my head around whether this currently actually
works. Can you verify that you can use setgroups=deny with a negative
acl in the initial user_ns to prevent a user doing the equivalent of
lxc-usernsexec -m b:0:$(id -u):1 to get around the acl?