Y
Hacker News
new
|
ask
|
show
|
jobs
by
progval
15 days ago
Successful sudo from a cgroup still makes you root on the machine. What you want for this is user namespaces, not (just) cgroups.
1 comments
reactordev
15 days ago
yes, you would setup namespace and unshare it once mounted to isolate the sandbox so root only sees the sandbox / and not your /
link