commit | a85fb273c94648cbf20a5f9bcf8bbbb075f271ad | [log] [tgz] |
---|---|---|
author | Eric W. Biederman <ebiederm@xmission.com> | Tue Jul 31 01:14:12 2012 -0700 |
committer | Eric W. Biederman <ebiederm@xmission.com> | Mon Nov 19 05:59:17 2012 -0800 |
tree | bdfe3d662dd4a42673620067f21c7b6fedd04d27 | |
parent | 50804fe3737ca6a5942fdc2057a18a8141d00141 [diff] |
vfs: Allow chroot if you have CAP_SYS_CHROOT in your user namespace Once you are confined to a user namespace applications can not gain privilege and escape the user namespace so there is no longer a reason to restrict chroot. Acked-by: Serge Hallyn <serge.hallyn@canonical.com> Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>