Eric W. Biederman <ebiederm@xxxxxxxxxxxx> wrote: > Yes. It sounds like either we need to change something in the > implementation of keys so they have a clear user namespace owner > or implement capable_wrt_key_uidgid. I'm thinking on the lines of making keys belong to a namespace in some way, and automatically invalidating them when the owning namespace is deleted. This will cause all links to them to be gc'd and thence the keys themselves. David _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linuxfoundation.org/mailman/listinfo/containers