]> git.ipfire.org Git - thirdparty/man-pages.git/commitdiff
pid_namespaces.7: Update capability requirements for /proc/sys/kernel/ns_last_pid
authorMichael Kerrisk <mtk.manpages@gmail.com>
Tue, 27 Oct 2020 10:41:18 +0000 (11:41 +0100)
committerMichael Kerrisk <mtk.manpages@gmail.com>
Tue, 27 Oct 2020 13:51:44 +0000 (14:51 +0100)
Since Linux 5.9, CONFIG_CHECKPOINT_RESTORE also allows writing to
/proc/sys/kernel/ns_last_pid.

Signed-off-by: Michael Kerrisk <mtk.manpages@gmail.com>
man7/pid_namespaces.7

index 9d893fcf26c11d1c469cad03982b1f644921c85b..62ecd26a53566c22d844849e86faee7fc5e5468e 100644 (file)
@@ -372,6 +372,8 @@ and when this file is subsequently read it will show that PID.
 .IP
 This file is writable by a process that has the
 .B CAP_SYS_ADMIN
+or (since Linux 5.9)
+.B CAP_CHECKPOINT_RESTORE
 capability inside the user namespace that owns the PID namespace.
 .\" This ability is necessary to support checkpoint restore in user-space
 This makes it possible to determine the PID that is allocated