public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Allowing mapping supplemental groups in user namespace?
@ 2019-02-28 19:27 Dmitry Torokhov
  2019-03-28 18:05 ` Serge E. Hallyn
  0 siblings, 1 reply; 5+ messages in thread
From: Dmitry Torokhov @ 2019-02-28 19:27 UTC (permalink / raw)
  To: Eric W. Biederman; +Cc: lkml, Serge E. Hallyn

Hi Eric,

Currently, unless caller has CAP_SETGID in parent namespace, we can
only map effective group id in the new user namespace. Would it be
possible to relax this rule to also allow mapping of supplemental
groups (1:1) of the caller?

Thanks.

-- 
Dmitry

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2019-03-28 18:43 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-02-28 19:27 Allowing mapping supplemental groups in user namespace? Dmitry Torokhov
2019-03-28 18:05 ` Serge E. Hallyn
2019-03-28 18:30   ` Dmitry Torokhov
2019-03-28 18:37     ` Serge E. Hallyn
2019-03-28 18:43       ` Dmitry Torokhov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox