Post #1550841
2026-04-22 02:02 UTC
It seems that user-namespaces are always a trade-off of pros and cons, whether you choose to use them, use them only for privileged, or not at all. Granted, I consider specifically the benefits to sandboxing. Still, the matter that it creates an isolation specifically for users and then have syscalls/kernel think it's a general system-namespace privileged call, is just tricky.
Replies (0)
No replies.