From: Al Viro <viro@ZenIV.linux.org.uk>
To: Dmitry Vyukov <dvyukov@google.com>
Cc: David Howells <dhowells@redhat.com>,
LKML <linux-kernel@vger.kernel.org>,
Miklos Szeredi <mszeredi@suse.cz>,
syzkaller <syzkaller@googlegroups.com>,
Kostya Serebryany <kcc@google.com>,
Alexander Potapenko <glider@google.com>,
Eric Dumazet <edumazet@google.com>,
Sasha Levin <sasha.levin@oracle.com>,
Robert Swiecki <swiecki@google.com>,
Kees Cook <keescook@google.com>
Subject: Re: fs: sandboxed process brings host down
Date: Fri, 22 Jan 2016 21:21:57 +0000 [thread overview]
Message-ID: <20160122212157.GG17997@ZenIV.linux.org.uk> (raw)
In-Reply-To: <CACT4Y+aRgUi9CxMOi7GO3eU3aDZhOkpY9gbO1Qmt6=bAjLXTXQ@mail.gmail.com>
On Fri, Jan 22, 2016 at 10:06:14PM +0100, Dmitry Vyukov wrote:
> Hello,
>
> While running syzkaller fuzzer I hit the following problem. Supervisor
> process sandboxes worker processes that do random activities with
> CLONE_NEWUSER | CLONE_NEWNS | CLONE_NEWPID | CLONE_NEWUTS |
> CLONE_NEWNET | CLONE_NEWIPC | CLONE_IO, setrlimit, chroot, etc.
> Because of that worker process gains ability to bring whole machine
> down (does not happen without the sandbox).
AFAICS, what you are doing is essentially mount --rbind / / in infinite
loop in luserns. Which ends up eating all memory. There's any number
of ways to do the same. We can play whack-a-mole with them until the
kernel is completely ossified with accounting code of different sorts.
Or one can disable userns and be done with that.
next prev parent reply other threads:[~2016-01-22 21:22 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-01-22 21:06 fs: sandboxed process brings host down Dmitry Vyukov
2016-01-22 21:21 ` Al Viro [this message]
2016-01-22 21:38 ` Dmitry Vyukov
2016-01-22 21:55 ` Al Viro
2016-01-22 22:32 ` Robert Święcki
2016-01-22 21:46 ` Kees Cook
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160122212157.GG17997@ZenIV.linux.org.uk \
--to=viro@zeniv.linux.org.uk \
--cc=dhowells@redhat.com \
--cc=dvyukov@google.com \
--cc=edumazet@google.com \
--cc=glider@google.com \
--cc=kcc@google.com \
--cc=keescook@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mszeredi@suse.cz \
--cc=sasha.levin@oracle.com \
--cc=swiecki@google.com \
--cc=syzkaller@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.