On tor, 2016-10-13 at 15:26 +0200, Giuseppe Scrivano wrote: > I have more patches to bubblewrap: > > https://github.com/projectatomic/bubblewrap/pull/101 > > that are needed to run systemd in it. I think the overall design, > and > that some caps are left only when in a new user namespace is safe. > Anyway, they require a very accurate review, as a bug there can open > the > door to really bad things.
I'm pretty scared of these, they need a very thorough review. -- =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Alexander Larsson Red Hat, Inc al...@redhat.com alexander.lars...@gmail.com He's an impetuous arachnophobic dog-catcher with no name. She's a violent motormouth magician's assistant looking for love in all the wrong places. They fight crime!