google/gvisor

Implement /proc/sys/user/max_user_namespaces ?

Open

#11210 opened on Nov 22, 2024

View on GitHub
 (4 comments) (1 reaction) (0 assignees)Go (12,713 stars) (1,061 forks)batch import
good first issuetype: enhancement

Description

Description

Bubblewrap with option "--disable-userns" enabled fails to run in gvisor due to lack of /proc/sys/user/max_user_namespaces (relevant code). The option "--disable-userns" is set as default by flatpak, so adding /proc/sys/user/max_user_namespaces will make it possible to build and run flatpak in container with gvisor.

Is this feature related to a specific bug?

No response

Do you have a specific solution in mind?

No response

Contributor guide