Skip to content

Commit

Permalink
doc: add a little note about shared ns + LSMs
Browse files Browse the repository at this point in the history
We should add a little not about the race in the previous patch.

Signed-off-by: Tycho Andersen <tycho@tycho.ws>
  • Loading branch information
tych0 committed May 15, 2019
1 parent c74e921 commit 8de9038
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions doc/lxc.container.conf.sgml.in
Expand Up @@ -1722,6 +1722,12 @@ dev/null proc/kcore none bind,relative 0 0
process wants to inherit the other's network namespace it usually
needs to inherit the user namespace as well.
</para>

<para>
Note that without careful additional configuration of an LSM,
sharing user+pid namespaces with a task may allow that task to
escalate privileges to that of the task calling liblxc.
</para>
</listitem>
</varlistentry>
</variablelist>
Expand Down

0 comments on commit 8de9038

Please sign in to comment.