process must have the CAP_SETUID ( CAP_SETGID ) capability in the user namespace ... writing process has the CAP_SETUID ( CAP_SETGID ) capability in the parent user namespaceuser and group IDs: setuid (2) ( setgid (2)) Modify the process's real (and possibly ... seteuid (2), setfsgid (2), setfsuid (2), setgid (2), setgroups (2), setpgid (2), setresgid …send (2) sendmsg (2) sendto (2) setgid (2) setpgid (2) setsid (2) setsockopt (2) setuidSETFCAP systemd-nspawn (1) CAP_SETGID systemd-nspawn (1) CAP_SETPCAP systemd-nspawnfunctions are affected: exec () kill () seteuid () setegid () setgid () setuid () SEM - _POSIX_SEMAPHORES - _SC_SEMAPHORESgroup-ID (unless it has CAP_SETGID ). To receive a struct ucred messagefunctions employing this technique are provided for setgid (2), setuid (2), setegid (2), seteuidgroup-ID set-GID, setgid set-user-ID set-UID, setuid superuser super user, superalso the kernel source file Documentation/admin-guide/perf-security.rst . CAP_SETGID • Make arbitrary manipulations of process GIDs