Comment 12 for bug 1639345

Revision history for this message
Christian Brauner (cbrauner) wrote :

Maybe, but what I was worried about with this solution is that you still have /proc mounted and a process that escapes to the helper NS could then access restricted information from the init PIDNS by e.g. parsing /proc via readdir(). It's possible that I'm overthinking this though.