mirror of
https://github.com/ilyakooo0/nix-bundle.git
synced 2024-09-11 06:55:53 +03:00
dont leak the /proc/self/setgroups fd
This commit is contained in:
parent
5e49fbc4a0
commit
8a344343ba
@ -202,6 +202,7 @@ int main(int argc, char *argv[]) {
|
||||
int fd_setgroups = open("/proc/self/setgroups", O_WRONLY);
|
||||
if (fd_setgroups > 0) {
|
||||
write(fd_setgroups, "deny", 4);
|
||||
close(fd_setgroups);
|
||||
}
|
||||
|
||||
// map the original uid/gid in the new ns
|
||||
|
Loading…
Reference in New Issue
Block a user