Rethinking race-free process signaling
Rethinking race-free process signaling
Posted Apr 7, 2019 19:31 UTC (Sun) by jkowalski (guest, #131304)In reply to: Rethinking race-free process signaling by luto
Parent article: Rethinking race-free process signaling
... which is why if you want to do this with pidfds, you really want CAP_KILL on part of the opener (or cloning entity) in the owning userns.
You could also make it available to things with NNP set, and when cloning children, the PRIV_KILL, then pass it around, send signals. These all checks happen when the flag is used during pidfd_open or clonefd or whatever.
Do you see other cases where it could be a problem?