osbuild: Make a MS_NOSUID bind mount over /
authorColin Walters <walters@verbum.org>
Mon, 12 Dec 2011 17:13:32 +0000 (12:13 -0500)
committerColin Walters <walters@verbum.org>
Mon, 12 Dec 2011 17:13:32 +0000 (12:13 -0500)
commitdb9b7b7be6d45d628bed60ce96b51bc3768b2702
treed298f1c7e736ae9869ac0a99a329debc1fcc84a7
parentdc4164993b5d031507f73e82d124e6d1d392bf63
osbuild: Make a MS_NOSUID bind mount over /

This closes a serious issue in that we still do a uid switch to 0 when
executing a suid binary, even though we're not gaining capabilities.
src/ostbuild/ostbuild-user-chroot.c