Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's equivalent to setting no_new_privs on the container process, so it'd mean you have to grant a privelege to the container process if you want any children to have access to it. It sure sounds funny in a CVE context, though.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: