About Cap. #44
Container On Android Admin
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Some root managers or specific versions of managers differ in handling the cap of the container attach.
For example, KernelSU (11682) is executed on the host:
When attaching:
It can be seen that the cap boundary set of the container process under attach is correctly set, while the
Effective Capabilities SetandPermitted Capabilities Setare inherited from the host, and the actual cap of the container is not restricted.At present, the effective solution is to add
lxc.no_new_privs=1in the container config file or global config file to prevent the container from obtaining new privilege capabilities.Then the ability of attach will be normal:
Considering that this is a specific issue, is it necessary to enable
lxc.no_new_privson Android by default?Beta Was this translation helpful? Give feedback.
All reactions