[patch 1/1][RFC] do not sys_reboot when not in init_pid_ns

Serge E. Hallyn serue at us.ibm.com
Tue Nov 4 13:01:34 PST 2008


Quoting Daniel Lezcano (dlezcano at fr.ibm.com):
> Daniel Hokka Zakrisson wrote:
> > Daniel Lezcano wrote:
> > 
> > Wouldn't it be better to simply remove CAP_SYS_BOOT from containers
> > until sys_reboot emits some signal to userspace to restart/halt the
> > container? (This is what we do in Linux-VServer.)
> 
> Ok, I will try, thanks.
> 
> BTW, isn't possible that a process gave CAP_SYS_BOOT capability again to 
>   himself and being able to shutdown the host ? I guess I should remove 
> CAP_SETPCAP too, no ?

No, remove it from your bounding set.  You can never add bits back to
that set.  prctl(PR_CAPBSET_DROP, CAP_SYS_BOOT);

-serge


More information about the Containers mailing list