From mboxrd@z Thu Jan 1 00:00:00 1970 From: Lukasz Pawelczyk Subject: Re: [RFC] lsm: namespace hooks Date: Tue, 02 Dec 2014 13:43:13 +0100 Message-ID: <1417524193.1899.2.camel@samsung.com> References: <1417096866-25563-1-git-send-email-l.pawelczyk@samsung.com> <1417096866-25563-2-git-send-email-l.pawelczyk@samsung.com> <1417098928.1805.15.camel@samsung.com> <54773757.8090905@nod.at> <1417099455.1805.17.camel@samsung.com> <54773CE7.5040303@nod.at> <1417101060.1805.21.camel@samsung.com> <87d288zm3a.fsf@x220.int.ebiederm.org> <1417104439.1805.25.camel@samsung.com> <871tooy4nc.fsf@x220.int.ebiederm.org> <1417109911.1805.27.camel@samsung.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-reply-to: <1417109911.1805.27.camel-Sze3O3UU22JBDgjK7y7TUQ@public.gmane.org> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org To: "Eric W. Biederman" Cc: Vladimir Davydov , Miklos Szeredi , Lukasz Pawelczyk , Oleg Nesterov , David Howells , Mark Rustad , Juri Lelli , Richard Weinberger , Daeseok Youn , Ingo Molnar , Jeff Kirsher , David Rientjes , Alex Thorlton , Matthew Dempsky , Kees Cook , Nikolay Aleksandrov , Dario Faggioli , Al Viro , James Morris , "open list:ABI/API" , Linux Containers , LKML , Paul Moore List-Id: containers.vger.kernel.org On czw, 2014-11-27 at 18:38 +0100, Lukasz Pawelczyk wrote: > Right now the major issue I see is that LSM by itself is not defined how > it's going to behave. It's up to a specific LSM module. > > E.g. within the Smack namespace filling the map is a privileged > operation. So by tying them up you cripple the ability to create a fully > working user namespace as an unprivileged process. Entertaining the idea that LSM namespace would be tied to user namespace (as you suggested) how do you see the limitation I described above? -- Lukasz Pawelczyk Samsung R&D Institute Poland Samsung Electronics