cgroup2: allow mounting /sys/fs/cgroup in UserNS without unsharing CgroupNS #2159
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bind-mount
/sys/fs/cgroup
when we are in UserNS but CgroupNS is not unshared,because we cannot mount
cgroup2
.This behavior correspond to crun v0.10.2.
https://github.com/containers/crun/blob/4325a78320852aa5dacb4d403ae01b241413068c/src/libcrun/linux.c#L433-L459
Fix #2158
Signed-off-by: Akihiro Suda akihiro.suda.cz@hco.ntt.co.jp