utilize bindmount-v2 from linux-helpers collection to set AT_SYMLINK_NOFOLLOW flag...
commite2869e0a5aa58cfadc1b2b58d3c21ec7e8c19306
authorAndreas Hrubak <ad132454@uucp.hu>
Sat, 27 Jul 2024 16:47:06 +0000 (27 18:47 +0200)
committerAndreas Hrubak <ad132454@uucp.hu>
Sat, 27 Jul 2024 16:47:06 +0000 (27 18:47 +0200)
tree84ac7873f20528d32fdcea01da34c8527473bd89
parent504574c38e93475e46686f83d1db3b9043fb767c
utilize bindmount-v2 from linux-helpers collection to set AT_SYMLINK_NOFOLLOW flag which is critical to prevent interception of /bin/sh to leak to the peer mount-namespaces in cases when /bin/sh is a symlink outside of /bin
root-tools/noshellinject