summaryrefslogtreecommitdiffhomepage
path: root/pkg/sentry/kernel/auth
diff options
context:
space:
mode:
Diffstat (limited to 'pkg/sentry/kernel/auth')
-rw-r--r--pkg/sentry/kernel/auth/user_namespace.go5
1 files changed, 1 insertions, 4 deletions
diff --git a/pkg/sentry/kernel/auth/user_namespace.go b/pkg/sentry/kernel/auth/user_namespace.go
index 5bb9c44c0..30957bb9a 100644
--- a/pkg/sentry/kernel/auth/user_namespace.go
+++ b/pkg/sentry/kernel/auth/user_namespace.go
@@ -49,10 +49,7 @@ type UserNamespace struct {
gidMapFromParent idMapSet
gidMapToParent idMapSet
- // TODO: Consider supporting disabling setgroups(2), which "was
- // added in Linux 3.19, but was backported to many earlier stable kernel
- // series, because it addresses a security issue" - user_namespaces(7). (It
- // was not backported to 3.11.10, which we are currently imitating.)
+ // TODO: Support disabling setgroups(2).
}
// NewRootUserNamespace returns a UserNamespace that is appropriate for a