[lxc-devel] problem with user namespace as root

Serge Hallyn serge.hallyn at ubuntu.com
Wed Feb 12 16:14:59 UTC 2014


Quoting Stephan Sachse (ste.sachse at gmail.com):
> > > where is the fault?
> >
> > I suspect lxc.autodev is the problem, as far as I know (and the above
> > seems to prove it), it doesn't work with unprivileged containers as it
> > currently requires the ability to mknod.
> 
> why? cap_mknod is not dropped and die cgroup.devices allows to create
> the null device.

The kernel does not allow mknod in non-init user namespaces.


More information about the lxc-devel mailing list