So would a namespace aware check for CAP_SYS_AUDIT say "no" then? (The
audit subsystem isn't namespace aware right now). How would such a check
look like in userspace?

CAP_SYS_ADMIN is a different beast, as this contains a lot of different
and unrelated  issues. It's also not fine-grained enough anyway for the
above purpose of "can we mount", as this can't/doesn't consider MACs. So
with the statement above (keeping all caps in a container) this means
that the failing dev-hugepages.mount is not easily fixable. It's also
mostly cosmetical, so not urgent for now. I guess the same goes for
iscsi/lvm2 etc.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1576341

Title:
  fails in lxd container

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lvm2/+bug/1576341/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to