3 ms·
Funny, the original commit message for that suggests it was simply a precaution. It's not out of the ordinary to avoid newer kernel features just in case. > Th
by epr 2y ago
Funny, the original commit message for that suggests it was simply a precaution. It's not out of the ordinary to avoid newer kernel features just in case.
> This is a short-term patch. Unprivileged use of CLONE_NEWUSER
is certainly an intended feature of user namespaces. However
for at least saucy we want to make sure that, if any security
issues are found, we have a fail-safe.
from: https://web.archive.org/web/20211022013829/https://kernel.ubuntu.com/git/serge/ubuntu-saucy.git/commit/?id=5c847404dcb2e3195ad0057877e1422ae90892b8 https://web.archive.org/web/20211022013829/https://kernel.ub...