Avoid messing up rootfs of the parent/only mount namespace for the
unusual case of a jailed process which does use namespaces, but
doesn't make use of mount namespaces.
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
- if (opts.namespace && build_jail_fs()) {
+ if ((opts.namespace & CLONE_NEWNS) && build_jail_fs()) {
ERROR("failed to build jail fs\n");
exit(EXIT_FAILURE);
}
ERROR("failed to build jail fs\n");
exit(EXIT_FAILURE);
}