All of lore.kernel.org
 help / color / mirror / Atom feed
From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
To: joeyli <jlee-IBi9RG/b67k@public.gmane.org>
Cc: Stephen Rothwell <sfr-3FnU+UHB4dNDw9hX6IcOSA@public.gmane.org>,
	Richard Weinberger <richard-/L3Ra7n9ekc@public.gmane.org>,
	Linux Containers
	<containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org>,
	Andy Lutomirski <luto-kltTT9wpgjJwATOyAt5JVQ@public.gmane.org>,
	Jim Fehlig <jfehlig-IBi9RG/b67k@public.gmane.org>,
	Cedric Bosdonnat <cbosdonnat-IBi9RG/b67k@public.gmane.org>
Subject: Re: What's the status of 87b47932 patch - mnt: Implicitly add MNT_NODEV on remount as we do on mount
Date: Sat, 29 Nov 2014 17:04:03 -0600	[thread overview]
Message-ID: <87k32dlicc.fsf@x220.int.ebiederm.org> (raw)
In-Reply-To: <20141127101105.GA30605-empE8CJ7fzk2xCFIczX1Fw@public.gmane.org> (joeyli's message of "Thu, 27 Nov 2014 18:11:05 +0800")

joeyli <jlee-IBi9RG/b67k@public.gmane.org> writes:

> Hi Eric, 
>
> Sorry for bother you. I saw your patch:
> 	mnt: Implicitly add MNT_NODEV on remount as we do on mount
>
> Already commited in linux-next:
> https://git.kernel.org/cgit/linux/kernel/git/next/linux-next.git/commit/fs/namespace.c?id=87b47932f40a11280584bce260cbdb3b5f9e8b7d
>
> But, I didn't see this patch show in v3.18-rc kernel in Linus's git tree.
> What's the status of 87b47932 patch? Does there have regression cases it
> could not be merged to v3.18 kernel?

The patch actually breaks remounting filesystems that did not have
MNT_NODEV set when theny were mounted.

The primary issue is that the bug hit at a very inopportune time in my
life (just before kernel summit) after which I had a vacation planned
and after that I had some serious job hunting and moving to do. 

Now I am busily trying to catch up on my queue and these long delayed
bug fixes are the next issue.

If folks can review/test the current version of the patch (to follow in
a moment) I would appreciate it.  Based on previous testing unless I
have a typo what I expect to see is:
lxc  - b0rked.  The old versions of lxc must be broken to fix the
       security issue.
libvirt-lxc - fixed.
Andy's thing - fixed.

Any comments on the next user namespace breaking security fix that is
being finalized would also be appreciated.

Eric

       reply	other threads:[~2014-11-29 23:04 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20141127101105.GA30605@linux-rxt1.site>
     [not found] ` <20141127101105.GA30605-empE8CJ7fzk2xCFIczX1Fw@public.gmane.org>
2014-11-29 23:04   ` Eric W. Biederman [this message]
     [not found]     ` <87k32dlicc.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2014-11-29 23:05       ` [CFT][PATCH] mnt: Implicitly add MNT_NODEV on remount when it was implicitly added by mount Eric W. Biederman
     [not found]         ` <87egsllia3.fsf_-_-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2014-11-30  0:07           ` Andy Lutomirski
     [not found]             ` <CALCETrX=B+0PVe8fhvCEyqBGD-D1wLJPd6CrqPn6LCGYgzxPMg-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-11-30 18:46               ` Eric W. Biederman
2014-11-30 14:58           ` Richard Weinberger
     [not found]             ` <547B309E.9020706-/L3Ra7n9ekc@public.gmane.org>
2014-11-30 15:00               ` Andy Lutomirski
     [not found]                 ` <CALCETrUZRi=Y=CDTpq5oO-tPOvMsZ+osKiydkCk-P0dn4DKJkA-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-11-30 15:16                   ` Richard Weinberger
     [not found]                     ` <547B34C6.6030709-/L3Ra7n9ekc@public.gmane.org>
2014-11-30 15:37                       ` Andy Lutomirski
     [not found]                         ` <CALCETrW6QRRB_DfHwYv+UVJ_8yF+8Db+UP+ezd4jG599b4dSiA-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2014-11-30 17:14                           ` Richard Weinberger
     [not found]                             ` <547B5066.4020509-/L3Ra7n9ekc@public.gmane.org>
2014-11-30 18:35                               ` Eric W. Biederman
     [not found]                                 ` <871tokleo7.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2014-11-30 18:42                                   ` Richard Weinberger
     [not found]                                     ` <547B6531.40504-/L3Ra7n9ekc@public.gmane.org>
2014-12-01  1:29                                       ` Eric W. Biederman
     [not found]                                         ` <87k32ci2dx.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2014-12-02  8:26                                           ` Richard Weinberger
     [not found]                                             ` <547D77C8.7050100-/L3Ra7n9ekc@public.gmane.org>
2014-12-02  9:53                                               ` Eric W. Biederman
     [not found]                                                 ` <87ppc22x9d.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org>
2014-12-02 13:12                                                   ` joeyli
2014-12-01  7:32       ` What's the status of 87b47932 patch - mnt: Implicitly add MNT_NODEV on remount as we do on mount joeyli

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87k32dlicc.fsf@x220.int.ebiederm.org \
    --to=ebiederm-as9lmozglivwk0htik3j/w@public.gmane.org \
    --cc=cbosdonnat-IBi9RG/b67k@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=jfehlig-IBi9RG/b67k@public.gmane.org \
    --cc=jlee-IBi9RG/b67k@public.gmane.org \
    --cc=luto-kltTT9wpgjJwATOyAt5JVQ@public.gmane.org \
    --cc=richard-/L3Ra7n9ekc@public.gmane.org \
    --cc=sfr-3FnU+UHB4dNDw9hX6IcOSA@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.