[lxc-devel] problem with user namespace as root
Serge Hallyn
serge.hallyn at ubuntu.com
Wed Feb 12 16:14:59 UTC 2014
Quoting Stephan Sachse (ste.sachse at gmail.com):
> > > where is the fault?
> >
> > I suspect lxc.autodev is the problem, as far as I know (and the above
> > seems to prove it), it doesn't work with unprivileged containers as it
> > currently requires the ability to mknod.
>
> why? cap_mknod is not dropped and die cgroup.devices allows to create
> the null device.
The kernel does not allow mknod in non-init user namespaces.
More information about the lxc-devel
mailing list