Re: [PATCH RFC] user-namespaced file capabilities - now with even more magic

From: Serge E. Hallyn
Date: Tue Nov 29 2016 - 16:29:59 EST


Quoting Michael Kerrisk (man-pages) (mtk.manpages@xxxxxxxxx):
> On 11/25/2016 06:50 PM, Serge E. Hallyn wrote:
> > On Fri, Nov 25, 2016 at 09:33:50AM +0100, Michael Kerrisk (man-pages) wrote:
> >> Hi Serge,
> >>
> >> On 11/24/2016 11:52 PM, Serge E. Hallyn wrote:
> >>> Quoting Michael Kerrisk (man-pages) (mtk.manpages@xxxxxxxxx):
> >>
> >> [...]
> >>
> >>>> Could we have a man-pages patch for this feature? Presumably for
> >>>> user_namespaces(7) or capabilities(7).
> >>>
> >>> capabilities.7 doesn't actually mention anything about user namespaces
> >>> right now.
> >>
> >> True. There's really just this:
> >>
> >> Interaction with user namespaces
> >> For a discussion of the interaction of capabilities and user
> >> namespaces, see user_namespaces(7).
> >>
> >>> I'll come up with a patch for both I think. Do you have a
> >>> deadline for a new release coming up?
> >>
> >> No deadlines as such. The last couple of years, as a sort of
> >> experiment, I've fallen into the same release cycle as the kernel
> >> (typically making a release in the week or so after the kernel release),
> >> and I am even using a similar numbering scheme. Ideally, the man-pages
> >> patch would go into the release that corresponds to the kernel release
> >> that makes the change.
> >
> > Cool - I'll write something up in the next few weeks.
>
> Obviously, the sooner you write it, the sooner others may read--and
> perhaps test--it.

Hi,

first draft

https://git.kernel.org/cgit/linux/kernel/git/sergeh/man-pages.git/commit/?h=2016-11-29/nscaps