aboutsummaryrefslogtreecommitdiffstats
path: root/man/man2/unshare.2
diff options
context:
space:
mode:
Diffstat (limited to 'man/man2/unshare.2')
-rw-r--r--man/man2/unshare.211
1 files changed, 11 insertions, 0 deletions
diff --git a/man/man2/unshare.2 b/man/man2/unshare.2
index e724649505..79a960728b 100644
--- a/man/man2/unshare.2
+++ b/man/man2/unshare.2
@@ -461,6 +461,17 @@ Such functionality may be added in the future, if required.
.\"be incrementally added to unshare without affecting legacy
.\"applications using unshare.
.\"
+.PP
+Creating all kinds of namespace, except user namespaces, requires the
+.B CAP_SYS_ADMIN
+capability.
+However, since creating a user namespace automatically confers a full set of
+capabilities,
+creating both a user namespace and any other type of namespace in the same
+.BR unshare ()
+call does not require the
+.B CAP_SYS_ADMIN
+capability in the original namespace.
.SH EXAMPLES
The program below provides a simple implementation of the
.BR unshare (1)