logoalt Hacker News

yjftsjthsd-hyesterday at 3:36 PM1 replyview on HN

If you need root to set up the escape, then yes that is relatively uninteresting. Like, we know chroot can't contain root.


Replies

3formyesterday at 4:39 PM

Thanks. It was not evident from the example whether root inside of the sandbox is necessary - I assumed creating arbitrary symlinks doesn't require any particular capabilities, and there's nothing special about the locations.

Though it's not clear to me now:

- why was this patched then?

- is the point about root that non-root wouldn't have access to passwd anyway?

show 1 reply