All of lore.kernel.org
 help / color / mirror / Atom feed
From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
To: Zhao Hongjiang <zhaohongjiang37-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
Cc: containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org
Subject: Re: [PATCH 13/14] userns: On ia64 deal with current_uid and current_gid being kuid and kgid
Date: Tue, 25 Sep 2012 02:58:01 -0700	[thread overview]
Message-ID: <87wqzipgpi.fsf@xmission.com> (raw)
In-Reply-To: <50617630.1050709-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org> (Zhao Hongjiang's message of "Tue, 25 Sep 2012 17:15:28 +0800")

Zhao Hongjiang <zhaohongjiang37-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org> writes:

> On 2012-9-21 8:28, Eric W. Biederman wrote:
>> From: "Eric W. Biederman" <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
>> 
>> These ia64 uses of current_uid and current_gid slipped through the
>> cracks when I was converting everything to kuids and kgids convert
>> them now.
>> 
>> Cc: Tony Luck <tony.luck-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
>> Cc: Fenghua Yu <fenghua.yu-ral2JQCrhuEAvxtiuMwx3w@public.gmane.org>
>> Signed-off-by: "Eric W. Biederman" <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>

>> diff --git a/arch/ia64/kernel/signal.c b/arch/ia64/kernel/signal.c
>> index a199be1..37dd795 100644
>> --- a/arch/ia64/kernel/signal.c
>> +++ b/arch/ia64/kernel/signal.c
>> @@ -220,7 +220,7 @@ ia64_rt_sigreturn (struct sigscratch *scr)
>>  	si.si_errno = 0;
>>  	si.si_code = SI_KERNEL;
>>  	si.si_pid = task_pid_vnr(current);
>> -	si.si_uid = current_uid();
>> +	si.si_uid = from_kuid_munged(current_user_ns(), current_uid());
> Question: why use current_user_ns not the init_user_ns here?

Because the value is going to userspace and we want the userspace
value.

This is much less clear than I would like it.  In my ideal world we
would keep this value as a kuid_t right up until we perform the copy
to userspace.  Unfortunately I wasn't able to figure out to make
that happen.

However since this value is destined for user space there would
never be a reason to use &init_user_ns.  Values either stay
a kuid_t or are converted into the user namespace userspace needs.

Eric

  parent reply	other threads:[~2012-09-25  9:58 UTC|newest]

Thread overview: 57+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-09-21  0:26 [REVIEW][PATCH 00/14] userns: Miscelanous conversions Eric W. Biederman
     [not found] ` <87k3vote43.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-21  0:28   ` [PATCH 01/14] userns: Convert loop to use kuid_t instead of uid_t Eric W. Biederman
2012-09-21  0:28     ` Eric W. Biederman
     [not found]     ` <1348187330-6616-1-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-21  0:28       ` [PATCH 02/14] userns: Convert apparmor to use kuid and kgid where appropriate Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  0:28       ` [PATCH 03/14] userns: Convert tomoyo " Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  0:28       ` [PATCH 04/14] userns: Convert selinux " Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
     [not found]         ` <1348187330-6616-4-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-26 17:51           ` Serge Hallyn
2012-09-26 17:51         ` Serge Hallyn
2012-09-21  0:28       ` [PATCH 05/14] userns: Convert hostfs " Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-23 21:59         ` Richard Weinberger
2012-09-24  2:39           ` Eric W. Biederman
     [not found]           ` <505F864C.2000103-/L3Ra7n9ekc@public.gmane.org>
2012-09-24  2:39             ` Eric W. Biederman
2012-09-24 14:55             ` Serge Hallyn
2012-09-24 14:55               ` Serge Hallyn
     [not found]         ` <1348187330-6616-5-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-23 21:59           ` Richard Weinberger
2012-09-21  0:28       ` [PATCH 06/14] userns: Convert EVM to deal with kuids and kgids in it's hmac computation Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  0:28       ` [PATCH 07/14] userns: Add user namespace support to IMA Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  0:28       ` [PATCH 08/14] userns: Teach security_path_chown to take kuids and kgids Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  0:28       ` [PATCH 09/14] userns: Convert binder ipc to use kuids Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
     [not found]         ` <1348187330-6616-9-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-21  6:44           ` Greg Kroah-Hartman
2012-09-21  6:44             ` Greg Kroah-Hartman
2012-09-21  0:28       ` [PATCH 10/14] userns: Convert s390 hypfs to use kuid and kgid where appropriate Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-26 17:52         ` Serge Hallyn
     [not found]         ` <1348187330-6616-10-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-26 17:52           ` Serge Hallyn
2012-09-21  0:28       ` [PATCH 11/14] userns: Convert s390 getting uid and gid system calls to use kuid and kgid Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
     [not found]         ` <1348187330-6616-11-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-26 17:59           ` Serge Hallyn
2012-09-26 17:59         ` Serge Hallyn
2012-09-21  0:28       ` [PATCH 12/14] userns: On ppc convert current_uid from a kuid before printing Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
     [not found]         ` <1348187330-6616-12-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-26 17:56           ` Serge Hallyn
2012-09-26 17:56         ` Serge Hallyn
2012-09-21  0:28       ` [PATCH 13/14] userns: On ia64 deal with current_uid and current_gid being kuid and kgid Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
     [not found]         ` <1348187330-6616-13-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-25  9:15           ` Zhao Hongjiang
     [not found]             ` <50617630.1050709-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2012-09-25  9:58               ` Eric W. Biederman [this message]
2012-09-26 17:55           ` Serge Hallyn
2012-09-26 17:55         ` Serge Hallyn
2012-09-21  0:28       ` [PATCH 14/14] userns: On alpha modify linux_to_osf_stat to use convert from kuids and kgids Eric W. Biederman
2012-09-21  0:28         ` Eric W. Biederman
2012-09-21  6:07       ` [PATCH 01/14] userns: Convert loop to use kuid_t instead of uid_t Jens Axboe
2012-09-21  6:07     ` Jens Axboe
     [not found]       ` <505C0438.9060907-5c4llco8/ftWk0Htik3J/w@public.gmane.org>
2012-09-21  7:07         ` Eric W. Biederman
2012-09-21  7:07           ` Eric W. Biederman
     [not found]           ` <87sjabsvkx.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-09-21  7:11             ` Jens Axboe
2012-09-21  7:11               ` Jens Axboe
     [not found]               ` <505C1331.8050907-5c4llco8/ftWk0Htik3J/w@public.gmane.org>
2012-09-21  7:19                 ` Eric W. Biederman
2012-09-21  7:19                   ` Eric W. Biederman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87wqzipgpi.fsf@xmission.com \
    --to=ebiederm-as9lmozglivwk0htik3j/w@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=zhaohongjiang37-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.