Re: [CFT][PATCH 7/7] userns: Allow setting gid_maps without privilege when setgroups is disabled

2014-12-08 Thread Andy Lutomirski
On Mon, Dec 8, 2014 at 2:14 PM, Eric W. Biederman wrote: > > Now that setgroups can be disabled and not reenabled, setting gid_map > without privielge can now be enabled when setgroups is disabled. > > This restores most of the functionality that was lost when unprivilege unprivileged. > setting

[CFT][PATCH 7/7] userns: Allow setting gid_maps without privilege when setgroups is disabled

2014-12-08 Thread Eric W. Biederman
Now that setgroups can be disabled and not reenabled, setting gid_map without privielge can now be enabled when setgroups is disabled. This restores most of the functionality that was lost when unprivilege setting of gid_map was removed. Applications that use this functionality will need to chec