[PATCH] userns/capability: Add user namespace capability

2015-10-17 Thread Tobias Markus
..@vger.kernel.org Cc: linux-kernel@vger.kernel.org Cc: linux-...@vger.kernel.org Cc: linux-...@vger.kernel.org Cc: Eric W. Biederman Cc: Al Viro Cc: Serge Hallyn Cc: Andy Lutomirski Cc: Andrew Morton Cc: Christoph Lameter Cc: Michael Kerrisk Signed-off-by: Tobias Markus --- include/uapi/linux/capabi

Re: [PATCH] userns/capability: Add user namespace capability

2015-10-18 Thread Tobias Markus
On 17.10.2015 23:55, Serge E. Hallyn wrote: > On Sat, Oct 17, 2015 at 05:58:04PM +0200, Tobias Markus wrote: >> Add capability CAP_SYS_USER_NS. >> Tasks having CAP_SYS_USER_NS are allowed to create a new user namespace >> when calling clone or unshare with CLONE_NEW

Re: [PATCH] userns/capability: Add user namespace capability

2015-10-18 Thread Tobias Markus
On 17.10.2015 22:17, Richard Weinberger wrote: > On Sat, Oct 17, 2015 at 5:58 PM, Tobias Markus wrote: >> One question remains though: Does this break userspace executables that >> expect being able to create user namespaces without priviledge? Since >> creating us

Re: [PATCH] userns/capability: Add user namespace capability

2015-10-18 Thread Tobias Markus
On 18.10.2015 22:21, Richard Weinberger wrote: > Am 18.10.2015 um 22:13 schrieb Tobias Markus: >> On 17.10.2015 22:17, Richard Weinberger wrote: >>> On Sat, Oct 17, 2015 at 5:58 PM, Tobias Markus wrote: >>>> One question remains though: Does this break userspace exec

Re: [PATCH] userns/capability: Add user namespace capability

2015-10-18 Thread Tobias Markus
On 18.10.2015 22:48, Richard Weinberger wrote: > Am 18.10.2015 um 22:41 schrieb Tobias Markus: >> On 18.10.2015 22:21, Richard Weinberger wrote: >>> Am 18.10.2015 um 22:13 schrieb Tobias Markus: >>>> On 17.10.2015 22:17, Richard Weinberger wrote: >>>>