Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1443702

Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace

Path csiph.com!goblin2!goblin.stu.neva.ru!aioe.org!bofh.it!news.nic.it!robomod
From "W. Trevor King" <wking@tremily.us>
Newsgroups linux.kernel
Subject Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace
Date Thu, 14 Jul 2016 21:10:01 +0200
Message-ID <rUUbf-5bU-7@gated-at.bofh.it> (permalink)
References <rUTyx-4Je-5@gated-at.bofh.it> <rUTyy-4Je-41@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/simple; d=tremily.us; s=odin; t=1468523263; bh=1yB521wffOeSd3B4UbpEOAkb4SPbaJf7JWhP4fnTTLE=; h=Date:From:To:Cc:Subject:References:In-Reply-To; b=V+Qdk7EAxz0JviXdCZj+Hfvyu0iuA4XgQ7rDQo13+27mUbTduRqxGwpLVYcfKe6F3 QB6L9LFfxvodQxtwKCB1VvzJ4Q9BuPjxyA3l8do0s5Rf1iMw6Z7yvkalGvL0iUIWf9 3pCgh+a9p3NCEobIkpItIQ5Y1D4h02sHg+93IN9A=
MIME-Version 1.0
Content-Type multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="0F1p//8PRICkK4MW"
Content-Disposition inline
Openpgp id=39A2F3FA2AB17E5D8764F388FC29BDCDF15F5BE8; url=http://tremily.us/pubkey.txt
User-Agent Mutt/1.5.23 (2014-03-12)
X-Cmae-Envelope MS4wfGZR4s5Ozgi2+o6y9TUBLBDDNLvAcZNr7Co76RP38oXNDHNZxXsu4Gor+wevxsiiDbQIk9XCsfKK4emCuok9T9L2xn+kwrswhRBe0aZiIWtgDF44YcUp ouCpxG9iLsqeCxxtf+9FF9z1Ak0RnZVj6RT3l+X2yTTIIDCQXCaxXu1+Sc9FNUqRb8yKGj+OoS1prUhmQAjc7LECOdpCor5ia26m2UTkCvNZkqt8zLMHtIzC NeBp5NCJODWdvdDiZI3V755DMJFshJnAM3f2sdg26TJJdGDEYnqUj+f1U1bcPlELU8eQQZGfYp/QNxuS9xa0+FqlDXea8vcEGVJJrWWmBKH/+1o1RiYUspZS 6J4rPSv01mHDjwqjALyiMl3XJ57G7A==
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 92
Organization linux.* mail to news gateway
X-Original-Cc linux-kernel@vger.kernel.org, criu@openvz.org, linux-api@vger.kernel.org, containers@lists.linux-foundation.org, linux-fsdevel@vger.kernel.org
X-Original-Date Thu, 14 Jul 2016 12:07:42 -0700
X-Original-Message-ID <20160714190742.GA24913@odin.tremily.us>
X-Original-References <1468520419-28220-1-git-send-email-avagin@openvz.org> <1468520419-28220-3-git-send-email-avagin@openvz.org>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1443702

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On Thu, Jul 14, 2016 at 11:20:16AM -0700, Andrey Vagin wrote:
> +struct ns_common *ns_get_owner(struct ns_common *ns)
> +{
> +	const struct cred *cred = current_cred();
> +	struct user_namespace *user_ns, *p;
> +
> +	user_ns = p = ns->user_ns;
> +	if (user_ns == NULL) { /* ns is init_user_ns */
> +		/* Unprivileged user should not know that it's init_user_ns. */
> +		if (capable(CAP_SYS_ADMIN))
> +			return ERR_PTR(-ENOENT);
> +		return ERR_PTR(-EPERM);
> +	}
> +
> +	for (;;) {
> +		if (p == cred->user_ns)
> +			break;
> +		if (p == &init_user_ns)
> +			return ERR_PTR(-EPERM);
> +		p = p->parent;
> +	}
> +
> +	return &get_user_ns(user_ns)->ns;
> +}

I'm still not sure we need the CAP_SYS_ADMIN check [1].  Maybe “you
have an open file descriptor for the namespace” means you've already
been authorized to access the parent information (e.g. via POSIX
permissions on /proc/<pid>/ns/… or the bind-mounted namespace).
Whether you can get the parent information probably depends whether
you can use setns to join the parent namespace (I haven't looked up
the backing code for that).

But whichever way we go there, I think we do want to be consistent
between init_user_ns and other namespaces.  So we should have a
CAP_SYS_ADMIN check for init_user_ns if and only if we also have a
CAP_SYS_ADMIN check for the returned parent in the non-init_user_ns
case as well:

  user_ns = p = ns->user_ns;
  if (user_ns == NULL) { /* ns is init_user_ns */
    /* Unprivileged user should not know that it's init_user_ns. */
    if (capable(CAP_SYS_ADMIN))
      return ERR_PTR(-ENOENT);
     return ERR_PTR(-EPERM);
  } else if (! capable_in(user_ns, CAP_SYS_ADMIN)) {
    /* Unprivileged user should not know about the owning user ns. */
    return ERR_PTR(-ENOENT);
  }

Although I'm not sure what the real name for capable_in is, or even if
it exists.

Cheers,
Trevor

[1]: https://github.com/avagin/linux-task-diag/commit/2663bc803d324785e328261f3c07a0fef37d2088#commitcomment-18223327

-- 
This email may be signed or encrypted with GnuPG (http://www.gnupg.org).
For more information, see http://en.wikipedia.org/wiki/Pretty_Good_Privacy

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 0/5 RFC] Add an interface to discover relationships between namespaces Andrey Vagin <avagin@openvz.org> - 2016-07-14 20:30 +0200
  [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace Andrey Vagin <avagin@openvz.org> - 2016-07-14 20:30 +0200
    Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace  for a namespace "W. Trevor King" <wking@tremily.us> - 2016-07-14 21:10 +0200
  Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces Andrey Vagin <avagin@openvz.org> - 2016-07-15 00:10 +0200
    [PATCH 5/5] tools/testing: add a test to check nsfs ioctl-s Andrey Vagin <avagin@openvz.org> - 2016-07-15 04:20 +0200
    [PATCH 4/5] nsfs: add ioctl to get a parent namespace Andrey Vagin <avagin@openvz.org> - 2016-07-15 04:20 +0200
      Re: [PATCH 4/5] nsfs: add ioctl to get a parent namespace ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 07:30 +0200
    [PATCH 3/5] nsfs: add ioctl to get an owning user namespace for ns file descriptor Andrey Vagin <avagin@openvz.org> - 2016-07-15 04:20 +0200
    [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace Andrey Vagin <avagin@openvz.org> - 2016-07-15 04:20 +0200
      Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 07:20 +0200
        Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace for a namespace ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 16:50 +0200
          Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace  for a namespace "W. Trevor King" <wking@tremily.us> - 2016-07-24 19:10 +0200
      Re: [PATCH 2/5] kernel: add a helper to get an owning user namespace  for a namespace "W. Trevor King" <wking@tremily.us> - 2016-07-24 19:00 +0200
    Re: [PATCH 1/5] namespaces: move user_ns into ns_common ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 07:20 +0200
    Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 07:30 +0200
  Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "Michael Kerrisk (man-pages)" <mtk.manpages@gmail.com> - 2016-07-21 16:50 +0200
    Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces Andrey Vagin <avagin@openvz.org> - 2016-07-22 20:30 +0200
      Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "Michael Kerrisk (man-pages)" <mtk.manpages@gmail.com> - 2016-07-25 13:50 +0200
        Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-25 15:40 +0200
          Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "Michael Kerrisk (man-pages)" <mtk.manpages@gmail.com> - 2016-07-25 16:50 +0200
            Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "Serge E. Hallyn" <serge@hallyn.com> - 2016-07-25 17:00 +0200
              Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-25 17:40 +0200
            Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-25 17:20 +0200
  Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "W. Trevor King" <wking@tremily.us> - 2016-07-23 23:20 +0200
    Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces James Bottomley <James.Bottomley@HansenPartnership.com> - 2016-07-23 23:40 +0200
      Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "W. Trevor King" <wking@tremily.us> - 2016-07-24 00:10 +0200
        Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 00:20 +0200
          Re: [PATCH 0/5 RFC] Add an interface to discover relationships  between namespaces "W. Trevor King" <wking@tremily.us> - 2016-07-24 00:40 +0200
            Re: [PATCH 0/5 RFC] Add an interface to discover relationships between namespaces ebiederm@xmission.com (Eric W. Biederman) - 2016-07-24 07:10 +0200

csiph-web