500줄 코드로 Linux 컨테이너 만들기
Linux containers in 500 lines of code
Linux 컨테이너의 핵심 원리를 500줄 코드로 구현한 글. user namespace, pid namespace, mount namespace 등을 활용해 컨테이너를 직접 만드는 과정을 설명한다. 특히 unprivileged user namespace가 커널 공격 표면을 넓힐 수 있다는 보안 우려와 각 배포판의 대응을 다룬다. Ubuntu와 Debian은 sysctl로 비활성화할 수 있게 패치했고, Grsecurity는 CAP_SYS_ADMIN 등이 없으면 아예 막으며, Arch Linux는 기본적으로 꺼져 있다.
If a (real) root user has had the SYS_CAP_ADMIN capability removed, but then creates a user namespace, this capability is restored for the (fake) root user.