OL> I'm ok with that. My only concern was CAP_NET_ADMIN - so the input OL> should come from network people - is it ok with them to use OL> CAP_SYS_ADMIN there "instead" ? I meant CAP_NET_ADMIN of course :) I'll merge that check in with the sysctl one and then see what they have to say about the whole thing. My guess would be that this particular part will not be the most controversial bit :) I'll post v5 here in a few and copy netdev. Thanks! -- Dan Smith IBM Linux Technology Center email: danms@xxxxxxxxxx _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linux-foundation.org/mailman/listinfo/containers