Unprivileged containers and co-ordinating user namespaces

W. Trevor King wking at tremily.us
Thu Apr 28 23:00:46 UTC 2016


On Thu, Apr 28, 2016 at 03:02:08PM -0700, James Bottomley wrote:
> /etc/usernamespaces
> 
> and the format be <user>:<start>:<length>:<flags>
>
>> 
> If this sounds OK to people, I can code up a utility that does this,
> which should probably belong in util-linux.

This sounds a lot like shadow's newuidmap and newgidmap [1,2,3].

Cheers,
Trevor

[1]: https://github.com/shadow-maint/shadow/commit/673c2a6f9aa6c69588f4c1be08589b8d3475a520
[2]: http://man7.org/linux/man-pages/man1/newuidmap.1.html
[3]: http://man7.org/linux/man-pages/man5/subuid.5.html

-- 
This email may be signed or encrypted with GnuPG (http://www.gnupg.org).
For more information, see http://en.wikipedia.org/wiki/Pretty_Good_Privacy
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.linuxfoundation.org/pipermail/containers/attachments/20160428/fa8725fd/attachment.sig>


More information about the Containers mailing list