angler-fishThe Vulnerability History Project

nss-mymachines: map userns users of containers to real user names

      Given a container "foo", that maps user id $UID to container user, using
user namespaces, this NSS module extenstion will now map the $UID to a
name "vu-foo-$TUID" for the translated UID $UID.

Similar, userns groups are mapped to "vg-foo-$TGID" for translated GIDs
of $GID.

This simple change should make userns users more discoverable. Also,
given that many tools like "adduser" check NSS before allocating a UID,
should lower the chance of UID range conflicts between tools.
    
commit c01ff965b48bb9693dcd77cbc748b5d8676766b0
+15 -20
-13
-2
+1 -230
-16
+1 -319
-4
+2 -31
expand_less