Linux Container Development
 help / color / mirror / Atom feed
From: "Serge E. Hallyn" <serge@hallyn.com>
To: Alexey Dobriyan <adobriyan@gmail.com>
Cc: "Serge E. Hallyn" <serue@us.ibm.com>,
	Linux Containers <containers@lists.osdl.org>,
	David Howells <dhowells@redhat.com>,
	linux-security-module@vger.kernel.org
Subject: Re: [PATCH 6/8] cr: checkpoint and restore task credentials
Date: Thu, 28 May 2009 09:01:10 -0500	[thread overview]
Message-ID: <20090528140110.GA772@hallyn.com> (raw)
In-Reply-To: <20090527183610.GA31930@x200.localdomain>

Quoting Alexey Dobriyan (adobriyan@gmail.com):
> On Tue, May 26, 2009 at 12:33:54PM -0500, Serge E. Hallyn wrote:
> > +struct ckpt_hdr_cred {
> > +	struct ckpt_hdr h;
> > +	__u32 version; /* especially since capability sets might grow */
> 
> Oh, no. Image version should be incremented.

Why?  The format hasn't changed since my last set I don't think...

Oh, I added the padding.  Thanks.  I have to bump it again for the
next set (hopefully out today or tomorrow) as it adds securebits.
(And hopefully a first stab at LSM, though it's not looking
likely)

> > +	__u32 uid, suid, euid, fsuid;
> > +	__u32 gid, sgid, egid, fsgid;
> > +	__u64 cap_i, cap_p, cap_e;
> > +	__u64 cap_x;  /* bounding set ('X') */
> > +	__s32 user_ref;
> > +	__s32 groupinfo_ref;
> > +	__u32 padding;
> > +} __attribute__((aligned(8)));
> > +
> > +struct ckpt_hdr_groupinfo {
> > +	struct ckpt_hdr h;
> > +	__u32 ngroups;
> > +	/*
> > +	 * This is followed by ngroups __u32s
> > +	 */
> > +	__u32 groups[0];
> > +} __attribute__((aligned(8)));
> 
> > --- a/include/linux/sched.h
> > +++ b/include/linux/sched.h
> > @@ -1871,6 +1871,12 @@ static inline struct user_struct *get_uid(struct user_struct *u)
> >  extern void free_uid(struct user_struct *);
> >  extern void release_uids(struct user_namespace *ns);
> >  
> > +#ifdef CONFIG_CHECKPOINT
> > +struct ckpt_ctx;
> > +int checkpoint_write_user(struct ckpt_ctx *, struct user_struct *);
> > +struct user_struct *restore_read_user(struct ckpt_ctx *);
> > +#endif
> 
> I'll rip credential stuff from sched.h, better not add more.

Yeah I'll move this in cred.h.

...

> > +#define CKPT_MAXGROUPS 100
> > +#define MAX_GROUPINFO_SIZE (sizeof(*h)+CKPT_MAXGROUPS*sizeof(gid_t))
> > +struct group_info *restore_read_groupinfo(struct ckpt_ctx *ctx)
> > +{
> > +	struct group_info *g;
> > +	struct ckpt_hdr_groupinfo *h;
> > +	int i;
> > +
> > +	h = ckpt_read_buf_type(ctx, MAX_GROUPINFO_SIZE, CKPT_HDR_GROUPINFO);
> > +	if (IS_ERR(h))
> > +		return ERR_PTR(PTR_ERR(h));
> > +	if (h->ngroups > CKPT_MAXGROUPS) {
> > +		g = ERR_PTR(-EINVAL);
> > +		goto out;
> > +	}
> > +	g = groups_alloc(h->ngroups);
> > +	if (!g) {
> > +		g = ERR_PTR(-ENOMEM);
> > +		goto out;
> > +	}
> > +	for (i = 0; i < h->ngroups; i++)
> > +		GROUP_AT(g, i) = h->groups[i];
> > +
> > +out:
> > +	ckpt_hdr_put(ctx, h);
> > +	return g;
> > +}
> 
> No checks, that groups in image are a) sorted, b) ->ngroups is compatible
> with object image.

Thanks, will fix.

So I'd like to suggest that we take the pieces that we can both use
(the code in groups.c, cred.c, security/security.c, and capabilities)
and get it identical between both versions.  But we would need to
find a way to ignore API differences for reading and writing the
checkpoint file.

BTW I have some credentials (users, user namespaces, and securebits)
testcases under cr_tests/userns/ in git://git.sr71.net/~hallyn/cr_tests.git.
Maybe you can reuse some of that for your own testing.

thanks,
-serge

  reply	other threads:[~2009-05-28 14:01 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-05-26 17:32 [PATCH 0/8] a start to credentials c/r Serge E. Hallyn
2009-05-26 17:33 ` [PATCH 1/8] cr: break out new_user_ns() Serge E. Hallyn
2009-05-26 17:33 ` [PATCH 2/8] cr: split core function out of some set*{u,g}id functions Serge E. Hallyn
2009-05-26 17:33 ` [PATCH 3/8] cr: capabilities: define checkpoint and restore fns Serge E. Hallyn
2009-05-26 17:33 ` [PATCH 4/8] groups: move code to kernel/groups.c Serge E. Hallyn
2009-05-26 17:33 ` [PATCH 5/8] groups: allow compilation on s390x Serge E. Hallyn
2009-05-26 23:17   ` Serge E. Hallyn
     [not found] ` <20090526173242.GA13757-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-05-26 17:33   ` [PATCH 6/8] cr: checkpoint and restore task credentials Serge E. Hallyn
2009-05-27 18:36     ` Alexey Dobriyan
2009-05-28 14:01       ` Serge E. Hallyn [this message]
2009-05-28 14:36         ` Alexey Dobriyan
2009-05-26 17:34 ` [PATCH 7/8] cr: restore file->f_cred Serge E. Hallyn
2009-05-26 17:34 ` [PATCH 8/8] user namespaces: debug refcounts Serge E. Hallyn
2009-05-27  3:05 ` [PATCH 0/8] a start to credentials c/r Casey Schaufler
2009-05-27 12:37   ` Serge E. Hallyn
2009-05-27 16:03     ` Casey Schaufler
2009-05-27 18:24       ` Serge E. Hallyn

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090528140110.GA772@hallyn.com \
    --to=serge@hallyn.com \
    --cc=adobriyan@gmail.com \
    --cc=containers@lists.osdl.org \
    --cc=dhowells@redhat.com \
    --cc=linux-security-module@vger.kernel.org \
    --cc=serue@us.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox