process wants to inherit the other's network namespace it usually
needs to inherit the user namespace as well.
</para>
+
+ <para>
+ Note that without careful additional configuration of an LSM,
+ sharing user+pid namespaces with a task may allow that task to
+ escalate privileges to that of the task calling liblxc.
+ </para>
</listitem>
</varlistentry>
</variablelist>
<para>
Specifying "errno" as action will cause LXC to register a seccomp filter
- that will cause a specific errno to be returned ot the caller. The errno
+ that will cause a specific errno to be returned to the caller. The errno
value can be specified after the "errno" action word.
</para>