-
Notifications
You must be signed in to change notification settings - Fork 246
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Default to always (even privileged) run in a user namespace
Since we're setting NO_NEW_PRIVS, and are not generally running bubblewrap as the root user there is very little use for other uids. Additionally, this is the only mode which works when using unprivileged user namespaces, so it makes sense to use it by default. You can use --share-user to not use a user namespace, but that will not work unless bubblewrap is setuid.
- Loading branch information
1 parent
05762b4
commit e2b76fe
Showing
1 changed file
with
29 additions
and
15 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters