Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Andy Lutomirski
On Fri, Apr 11, 2014 at 3:46 PM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Fri, Apr 11, 2014 at 3:29 PM, Serge E. Hallyn wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> On Fri, Apr 11, 2014 at 2:52 PM, Serge E. Hallyn wrote: >> >> > Quoting An

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Fri, Apr 11, 2014 at 3:29 PM, Serge E. Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On Fri, Apr 11, 2014 at 2:52 PM, Serge E. Hallyn wrote: > >> > Quoting Andy Lutomirski (l...@amacapital.net): > >> >> On Mon, Apr 7, 201

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Andy Lutomirski
On Fri, Apr 11, 2014 at 3:29 PM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Fri, Apr 11, 2014 at 2:52 PM, Serge E. Hallyn wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> On Mon, Apr 7, 2014 at 11:13 AM, Serge E. Hallyn wrote: >> >> > Quoting An

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Fri, Apr 11, 2014 at 2:52 PM, Serge E. Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On Mon, Apr 7, 2014 at 11:13 AM, Serge E. Hallyn wrote: > >> > Quoting Andy Lutomirski (l...@amacapital.net): > >> >> I'm starting to th

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Andy Lutomirski
On Fri, Apr 11, 2014 at 2:52 PM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Mon, Apr 7, 2014 at 11:13 AM, Serge E. Hallyn wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> I'm starting to think that we need to extend dumpable to something >> >> mu

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-11 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Mon, Apr 7, 2014 at 11:13 AM, Serge E. Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> I'm starting to think that we need to extend dumpable to something > >> much more general like a list of struct creds that someone needs

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-10 Thread Andy Lutomirski
On Mon, Apr 7, 2014 at 11:13 AM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> I'm starting to think that we need to extend dumpable to something >> much more general like a list of struct creds that someone needs to be >> able to ptrace, *in addition to current creds*

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-07 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Fri, Apr 4, 2014 at 12:10 PM, Serge Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On Fri, Apr 4, 2014 at 11:30 AM, Serge Hallyn > >> wrote: > >> > Quoting Andy Lutomirski (l...@amacapital.net): > >> >> On 04/02/2014 10:3

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-04 Thread Andy Lutomirski
On Fri, Apr 4, 2014 at 12:10 PM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Fri, Apr 4, 2014 at 11:30 AM, Serge Hallyn >> wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> On 04/02/2014 10:32 AM, Serge E. Hallyn wrote: >> >> > (Sorry - the lxc-devel

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-04 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Fri, Apr 4, 2014 at 11:30 AM, Serge Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On 04/02/2014 10:32 AM, Serge E. Hallyn wrote: > >> > (Sorry - the lxc-devel list has moved, so replying to all with the > >> > correct list

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-04 Thread Andy Lutomirski
On Fri, Apr 4, 2014 at 11:30 AM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On 04/02/2014 10:32 AM, Serge E. Hallyn wrote: >> > (Sorry - the lxc-devel list has moved, so replying to all with the >> > correct list address; please reply to this rather than my previous

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-04 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On 04/02/2014 10:32 AM, Serge E. Hallyn wrote: > > (Sorry - the lxc-devel list has moved, so replying to all with the > > correct list address; please reply to this rather than my previous > > email) > > > > Quoting Serge Hallyn (serge.hal...@ubun

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-04 Thread Andy Lutomirski
On 04/02/2014 10:32 AM, Serge E. Hallyn wrote: > (Sorry - the lxc-devel list has moved, so replying to all with the > correct list address; please reply to this rather than my previous > email) > > Quoting Serge Hallyn (serge.hal...@ubuntu.com): >> Hi Eric, >> >> (sorry, I don't seem to have the

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-02 Thread Serge E. Hallyn
(Sorry - the lxc-devel list has moved, so replying to all with the correct list address; please reply to this rather than my previous email) Quoting Serge Hallyn (serge.hal...@ubuntu.com): > Hi Eric, > > (sorry, I don't seem to have the email I actually wanted to reply > to in my mbox, but it i

Re: [lxc-devel] Kernel bug? Setuid apps and user namespaces

2014-04-02 Thread Serge Hallyn
Hi Eric, (sorry, I don't seem to have the email I actually wanted to reply to in my mbox, but it is https://lists.linuxcontainers.org/pipermail/lxc-devel/2013-October/005857.html) You'd said, > Someone needs to read and think through all of the corner cases and see > if we can ever have a time wh