procfs and sysfs

Several files under /proc and /sys are not data but control knobs: write a path into them and the kernel runs that program later, in the host's context, as root. These are safe only because a normal container does not get a writable host /proc or /sys. When one is bind-mounted in (a surprisingly common misconfiguration) or the container holds CAP_SYS_ADMIN in the initial namespaces, each knob becomes an escape. The catch shared by the executable-handler knobs is that the path must be reachable in the host filesystem namespace, so the helper is dropped on a host-visible path such as the container's overlay upperdir.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more