All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v4 0/3] proc: Relax check of mount visibility
@ 2020-11-06 15:15 Alexey Gladkov
  2020-11-06 15:15 ` [PATCH v4 1/3] " Alexey Gladkov
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Alexey Gladkov @ 2020-11-06 15:15 UTC (permalink / raw)
  To: LKML, Linux FS Devel, Eric W . Biederman
  Cc: Alexey Gladkov, Alexander Viro, Kees Cook

If only the dynamic part of procfs is mounted (subset=pid), then there is no
need to check if procfs is fully visible to the user in the new user namespace.

Changelog
---------
v4:
* Set SB_I_DYNAMIC only if pidonly is set.
* Add an error message if subset=pid is canceled during remount.

v3:
* Add 'const' to struct cred *mounter_cred (fix kernel test robot warning).

v2:
* cache the mounters credentials and make access to the net directories
  contingent of the permissions of the mounter of procfs.

--

Alexey Gladkov (3):
  proc: Relax check of mount visibility
  proc: Show /proc/self/net only for CAP_NET_ADMIN
  proc: Disable cancellation of subset=pid option

 fs/namespace.c          | 27 ++++++++++++++++-----------
 fs/proc/proc_net.c      |  8 ++++++++
 fs/proc/root.c          | 29 ++++++++++++++++++++++-------
 include/linux/fs.h      |  1 +
 include/linux/proc_fs.h |  1 +
 5 files changed, 48 insertions(+), 18 deletions(-)

-- 
2.25.4


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-11-06 15:21 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-11-06 15:15 [PATCH v4 0/3] proc: Relax check of mount visibility Alexey Gladkov
2020-11-06 15:15 ` [PATCH v4 1/3] " Alexey Gladkov
2020-11-06 15:15 ` [PATCH v4 2/3] proc: Show /proc/self/net only for CAP_NET_ADMIN Alexey Gladkov
2020-11-06 15:15 ` [PATCH v4 3/3] proc: Disable cancellation of subset=pid option Alexey Gladkov

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.