Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you're confusing namespace and unix file permissions.

You can think of capability-restricted directory descriptors as (sort of) individual-fd chroots. File permissions still apply inside a chroot. But the namespace of anything outside the chroot is totally inaccessible.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: