Comment 3 for bug 827798

Revision history for this message
Serge Hallyn (serge-hallyn) wrote : Re: [Bug 827798] Re: LXC works without warning regardless if cgroup namespaces are properly available

Quoting Michael Casadevall (<email address hidden>):
> Thanks Serge. That behavior should be documented somewhere, since I was

Yup, lxc-checkconfig needs to be updated.

> greatly concerned there was a security issue in LXC.

Note that until lxc can exploit user namespaces, there are plenty of security
issues unless you lock it down with an LSM.

thanks,
-serge