Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Lai0chee
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
Lai0chee
12y ago
You seem to confuse "portable file format" with "horrible designed format". :-)
2.
▲
by
Lai0chee
12y ago
So, this is the justification for having a horrible file format?
3.
▲
by
Lai0chee
12y ago
Yessss, just down vote me for sharing my personal opinion.
4.
▲
by
Lai0chee
12y ago
How do other distros solve this "issue"?
5.
▲
by
Lai0chee
12y ago
I gave up on Debian after they've renamed Firefox to Iceweasel.
6.
▲
by
Lai0chee
12y ago
IMHO Debian's problem is not systemd the problem are the crazy politics. :-(
7.
▲
by
Lai0chee
12y ago
Is systemd now able to work within user namespaces?
8.
▲
by
Lai0chee
12y ago
BTW: Thanks for downvoting this.
9.
▲
by
Lai0chee
12y ago
There is a high chance that it will crash your system. - Unlocked access to ->comm - What if buf is less than 6 bytes or not NULL terminated? - Only searching for sys_close() is not enough, it will also find any function pointer to sys_c
10.
▲
by
Lai0chee
12y ago
BTW: Just one example of a typical Linux namespace vulnerability: http://git.kernel.org/cgit/linux/kernel/git/ebiederm/user-na...
11.
▲
by
Lai0chee
12y ago
Docker is based on Linux namespaces. The first thing which comes to mind is that Docker does not use user namespaces. Hence, the root within Docker is the same root as on the host side. Of course Docker papers over the issue by using apparm
12.
▲
by
Lai0chee
12y ago
Docker "isolation" is not as strong as most hipsters think. :-)
13.
▲
by
Lai0chee
12y ago
humm, the sudo makes me shudder.
14.
▲
by
Lai0chee
12y ago
Is there no at(1) on OSX?
15.
▲
by
Lai0chee
12y ago
This is the very best thing I've ever seen on this site. :-)
16.
▲
by
Lai0chee
12y ago
/me has a deja vu. Looks like this is Transmeta v2. :-)