Path: csiph.com!3.eu.feeder.erje.net!feeder.erje.net!usenet.goja.nl.eu.org!aioe.org!bofh.it!news.nic.it!robomod From: Nicolas Schier Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#969223: Can't rm directory on overlayfs in userns Date: Wed, 16 Sep 2020 10:10:01 +0200 Message-ID: References: X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Wed Sep 16 08:03:09 2020 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: -3.999 Reply-To: Nicolas Schier , 969223@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Debian Kernel Team X-Debian-Pr-Message: followup 969223 X-Debian-Pr-Package: src:linux X-Debian-Pr-Source: linux X-Spam-Bayes: score:0.0000 Tokens: new, 49; hammy, 150; neutral, 164; spammy, 0. spammytokens: hammytokens:0.000-+--H*UA:1.10.1, 0.000-+--H*u:1.10.1, 0.000-+--H*UA:2018-07-13, 0.000-+--H*u:2018-07-13, 0.000-+--UD:kernel.org Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fjasle.eu; s=mail; t=1600242798; bh=VYBVfvUZCkpJBrM/0DZrme0BNEzm2yZJN7DyJWcqMt8=; h=Date:From:To:Subject:References:In-Reply-To:From; b=t+qmwj2ZNKKCsugwVzDd4LooZfqEtQps1RF+b6VYymRSmJaQONorXd/NSkkyqzXqT Mr7RY7bnHTfNpwOKRtgXoofO/2Mul6NlQpMZzWx2hVlOK3gWmfDgnY6GcaDgvnMZOG MJmN1w4jUN9pVc9W/OOFKA4Rf9Iue0tdPWLruYQw= MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit User-Agent: Mutt/1.10.1 (2018-07-13) X-Provags-ID: V03:K1:lzWDOoME3u2+ifJYJ9RqoQ1cuCG/+6oqNlnT3RHleCwPPRYQ2FR xO3t4LujWb8xYylV+pTxzL4QMPazgxMZERAmNaIDRfNgIEvOsb7oZzTktYIcdtaCP4xf3Vn 2eiAnbJmJnommueBl888EpzRhLo128dERJFb3b3xUCO4neD20RII0YlEnR4I4KN6zolCt/g QRr9ys0B+IAF5tNGojRHg== X-Ui-Out-Filterresults: notjunk:1;V03:K0:zFqmCUs0xpo=:0ipjeYYldCwFDsyXqyzt8q Uc2f5irGnL5INaLJvLrTWpXWMMWijTlo03uBBQumfjffDObmk0YIZ08xaEnbWiWygEYuC2t0d hBcRMeWIRG9Evgk1VYcx5JGqBOS2b3gSLOHiYcdW69NX/8RiXmoSGKpPvy/O7TtJFmClEJq3z EFsSHKAzGjO/mj5oY3xP1kgNxX/u8aiZfJsxMYJzkr1jrjNlc50d+K4YPLxDvRqgEsVIy00Q5 ObEpeTeyw/CPB2d8FDoDuATemXzLpCYl4FmN/qLAs939VrZ7hWuulGEEwfs7XBCjNLKPLvaZ9 L+THnHw05c3kvc6L9eA8WNnqbc4A2MJgoAtVKIK3+g1RIY+XlWTN1pV5BPfV9BjnopI8/AVML FXH3qzNHP4MgWF5OCcmy5Guwayf8cm+dCfeiYO7yEWyuZaGAd9VD/OkiHtFzziVpsFTuvVx4x rw8UiYiwMGr/kr78wZt/9fGCqCyprrmC9HgsMfA47O9uAPXVsNIw4LL+ZadxjrOLiwhZm50ck 9xTNzr4qmriMP1S6I5TFpbWlz625dVsVPuPkhTRVJc3FqpqSprb/gH0+76WcFEcwmggb9DOax +4qDC2qr0597Oq6iLe2TtOMrVNQq34lC467HvNq7pJJ5G0cbW/e6J+fadDkBZ+sh6S5qph1U1 P//3+F2YA/0PA0cOQImpH+M3TOD63AZgOaFM5s3oMXqQTHIm5SUDee2w4tgY0/j9ghyNAUz+E mz5+fKNSagNygamBbeI3hjF2pBIbk3kJsOL9r0RS0wlsxJIxlcyHQ64Gg1lFS3qmuWrkbEjqz ePwImoo6yBJsvS9Xejql/2fMH1J+aXUN78LAG10AdYsOh69JCAfD4RuS8FiGCzmeRLiT7xe X-Debian-Message: from BTS X-Mailing-List: archive/latest/1623168 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 70 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Wed, 16 Sep 2020 09:53:18 +0200 X-Original-Message-ID: <20200916075317.GQ18520@fjasle.eu> X-Original-References: <20200829141322.GA197496@local.zhsj.me> <20200829141322.GA197496@local.zhsj.me> <20200829141322.GA197496@local.zhsj.me> Xref: csiph.com linux.debian.bugs.dist:1025278 linux.debian.kernel:68143 On Wed, Sep 02, 2020 at 11:52:41AM +0800, Shengjing Zhu wrote: > On Sat, Aug 29, 2020 at 10:13 PM Shengjing Zhu wrote: > > > > Source: linux > > Version: 5.7.10-1 > > Severity: normal > > > > Hi, > > > > After enabling overlayfs for userns, I find it doesn't work as expected. > > > > $ cat /sys/module/overlay/parameters/permit_mounts_in_userns > > Y > > > > zsj@debian:~/test$ pwd > > /home/zsj/test > > zsj@debian:~/test$ tree > > . > > ├── lower > > │ └── a > > │ └── a > > ├── merged > > ├── upper > > └── work > > > > zsj@debian:~/test$ unshare -m -U -r > > root@debian:~/test# mount -t overlay -o rw,lowerdir=/home/zsj/test/lower,upperdir=/home/zsj/test/upper,workdir=/home/zsj/test/work overlay /home/zsj/test/merged > > root@debian:~/test# rm -rf merged/a > > rm: cannot remove 'merged/a': Input/output error > > Hi, overlayfs uses filesystem xattrs to mark "whiteouts" and redirects of directories, which are only accessable for root (CAP_SYS_ADMIN), thus, not when overlay is mounted in a user namespace, cp. e.g. [1,2]. Ubuntu kernel "solves" this by skipping the "trusted."-xattr check, thus allowing setting and removal of 'trusted.overlay.*' xattrs from within user namespaces; but those are still visible in all other namespaces. A following overlayfs mount done by the real root user will use these modified xattrs. To me it would seem to be more adequate if overlayfs would use 'overlay.*' instead of 'trusted.overlay.*', if it is mounted in an unpriviledged user namespace. But this would make overlay mounts done by root incompatible with those done in a user namespace. Maybe you find #836211 to be related to this. [1]: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/fs/xattr.c?h=linux-5.7.y#n113 [2]: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/fs/xattr.c?h=linux-5.7.y#n1049 [3]: https://kernel.ubuntu.com/git/ubuntu/ubuntu-focal.git/commit/?id=111cd1a9840ce187e28b49fe4e77b9b5e84386b1 > If I upgrade a debian10 VM to testing, it seems to work. > However if I boot a new debian testing VM, it seems not to work. > Both VMs are downloaded from http://cdimage.debian.org/cdimage/cloud/ > What can be the difference here? I'm lost on debugging this.. This confuses me. Are you sure, you used the same kernel version on both VMs when mounting overlayfs in userns? Kind regards, Nicolas -- epost: nicolas@fjasle.eu irc://oftc.net/nsc ↳ gpg: 18ed 52db e34f 860e e9fb c82b 7d97 0932 55a0 ce7f -- frykten for herren er opphav til kunnskap --