Re: For review: user_namespaces(7) man page

2013-05-14 Thread Gao feng
On 04/30/2013 03:45 AM, Rob Landley wrote: > On 04/29/2013 02:45:45 AM, richard -rw- weinberger wrote: >> On Thu, Mar 21, 2013 at 4:52 PM, Michael Kerrisk (man-pages) >> wrote: >> > Hi Serge, >> > >> > On Fri, Mar 15, 2013 at 4:38 PM, Serge Hallyn >> > wrote: >> >> Hi, >> >> >> >> you mention th

Re: For review: user_namespaces(7) man page

2013-04-29 Thread richard -rw- weinberger
On Mon, Apr 29, 2013 at 9:45 PM, Rob Landley wrote: > On 04/29/2013 02:45:45 AM, richard -rw- weinberger wrote: >> >> On Thu, Mar 21, 2013 at 4:52 PM, Michael Kerrisk (man-pages) >> wrote: >> > Hi Serge, >> > >> > On Fri, Mar 15, 2013 at 4:38 PM, Serge Hallyn >> > wrote: >> >> Hi, >> >> >> >> yo

Re: For review: user_namespaces(7) man page

2013-04-29 Thread Rob Landley
On 04/29/2013 02:45:45 AM, richard -rw- weinberger wrote: On Thu, Mar 21, 2013 at 4:52 PM, Michael Kerrisk (man-pages) wrote: > Hi Serge, > > On Fri, Mar 15, 2013 at 4:38 PM, Serge Hallyn wrote: >> Hi, >> >> you mention that after creating a new user namespace you at first have >> all cap

Re: For review: user_namespaces(7) man page

2013-04-29 Thread richard -rw- weinberger
On Thu, Mar 21, 2013 at 4:52 PM, Michael Kerrisk (man-pages) wrote: > Hi Serge, > > On Fri, Mar 15, 2013 at 4:38 PM, Serge Hallyn wrote: >> Hi, >> >> you mention that after creating a new user namespace you at first have >> all capabilities in the new ns. You don't explicitly mention (or I >> mi

Re: For review: user_namespaces(7) man page

2013-03-21 Thread Michael Kerrisk (man-pages)
Hi Serge, On Fri, Mar 15, 2013 at 4:38 PM, Serge Hallyn wrote: > Hi, > > you mention that after creating a new user namespace you at first have > all capabilities in the new ns. You don't explicitly mention (or I > missed it - I did see the mention of securebits) that if you want to > keep those

Re: For review: user_namespaces(7) man page

2013-03-15 Thread Serge Hallyn
Hi, you mention that after creating a new user namespace you at first have all capabilities in the new ns. You don't explicitly mention (or I missed it - I did see the mention of securebits) that if you want to keep those capabilities after doing an exec, you need to first have something mapped t