Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1385324
| From | Seth Forshee <seth.forshee@canonical.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH v3 02/21] fs: Remove check of s_user_ns for existing mounts in fs_fully_visible() |
| Date | 2016-04-22 18:00 +0200 |
| Message-ID | <rqLES-4cJ-7@gated-at.bofh.it> (permalink) |
| References | <rqLlw-44Z-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
fs_fully_visible() ignores MNT_LOCK_NODEV when FS_USERS_DEV_MOUNT is not set for the filesystem, but there is a bug in the logic that may cause mounting to fail. It is doing this only when the existing mount is not in init_user_ns but should check the new mount instead. But the new mount is always in a non-init namespace when fs_fully_visible() is called, so that condition can simply be removed. Signed-off-by: Seth Forshee <seth.forshee@canonical.com> --- fs/namespace.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/fs/namespace.c b/fs/namespace.c index f20c82f91ecb..c133318bec35 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -3234,8 +3234,7 @@ static bool fs_fully_visible(struct file_system_type *type, int *new_mnt_flags) mnt_flags = mnt->mnt.mnt_flags; if (mnt->mnt.mnt_sb->s_iflags & SB_I_NOEXEC) mnt_flags &= ~(MNT_LOCK_NOSUID | MNT_LOCK_NOEXEC); - if (mnt->mnt.mnt_sb->s_user_ns != &init_user_ns && - !(mnt->mnt.mnt_sb->s_type->fs_flags & FS_USERNS_DEV_MOUNT)) + if (!(mnt->mnt.mnt_sb->s_type->fs_flags & FS_USERNS_DEV_MOUNT)) mnt_flags &= ~(MNT_LOCK_NODEV); /* Verify the mount flags are equal to or more permissive -- 1.9.1
Back to linux.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
[PATCH v3 00/21] Support fuse mounts in user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
[PATCH v3 17/21] capabilities: Allow privileged user in s_user_ns to set security.* xattrs Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
[PATCH v3 01/21] fs: fix a posible leak of allocated superblock Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
[PATCH v3 15/21] fs: Don't remove suid for CAP_FSETID in s_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:40 +0200
[PATCH v3 16/21] fs: Allow superblock owner to access do_remount_sb() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 05/21] block_dev: Check permissions towards block device inode when mounting Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 04/21] block_dev: Support checking inode permissions in lookup_bdev() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 12/21] fs: Refuse uid/gid changes which don't map into s_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
Re: [PATCH v3 14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids "Serge E. Hallyn" <serge@hallyn.com> - 2016-04-25 22:40 +0200
Re: [PATCH v3 14/21] fs: Allow superblock owner to change ownership of inodes with unmappable ids Seth Forshee <seth.forshee@canonical.com> - 2016-04-26 21:50 +0200
[PATCH v3 11/21] cred: Reject inodes with invalid ids in set_create_file_as() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 19/21] fuse: Support fuse filesystems outside of init_user_ns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 21/21] fuse: Allow user namespace mounts Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 20/21] fuse: Restrict allow_other to the superblock's namespace or a descendant Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 10/21] fs: Check for invalid i_uid in may_follow_link() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 09/21] Smack: Handle labels consistently in untrusted mounts Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 18/21] fuse: Add support for pid namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 08/21] userns: Replace in_userns with current_in_userns Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 17:50 +0200
[PATCH v3 06/21] fs: Treat foreign mounts as nosuid Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
[PATCH v3 07/21] selinux: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
[PATCH v3 03/21] fs: Allow sysfs and cgroupfs to share super blocks between user namespaces Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
Re: [PATCH v3 03/21] fs: Allow sysfs and cgroupfs to share super blocks between user namespaces "Serge E. Hallyn" <serge@hallyn.com> - 2016-04-25 21:10 +0200
[PATCH v3 02/21] fs: Remove check of s_user_ns for existing mounts in fs_fully_visible() Seth Forshee <seth.forshee@canonical.com> - 2016-04-22 18:00 +0200
csiph-web