From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Serge E. Hallyn" Subject: Re: User namespace feature freeze lifted Date: Tue, 15 Sep 2015 13:44:24 -0500 Message-ID: <20150915184424.GA21788@mail.hallyn.com> References: <87io7bd23x.fsf@x220.int.ebiederm.org> <20150915173633.GD4699@ubuntumail> <874mivd0ct.fsf@x220.int.ebiederm.org> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Content-Disposition: inline In-Reply-To: <874mivd0ct.fsf-JOvCrm2gF+uungPnsOpG7nhyD016LWXt@public.gmane.org> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org Errors-To: containers-bounces-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org To: "Eric W. Biederman" Cc: Seth Forshee , Linux Containers , Serge Hallyn , Andy Lutomirski List-Id: containers.vger.kernel.org On Tue, Sep 15, 2015 at 01:05:38PM -0500, Eric W. Biederman wrote: > Serge Hallyn writes: > > > Quoting Eric W. Biederman (ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org): > >> > >> As of v4.3-rc1 all of the security issues I am aware of with the user > >> namespace have been addressed. If someone knows of something I have > >> overlooked please let me know. > >> > >> As much as humanly possible I want to avoid security bugs in the future > >> so I will endeavour to ensure any future user namespace patches receive > >> a close review. > >> > >> As for merging features I expect I will likley start with Seth's code > >> for associating superblock with user namespaces, and then move on to > >> Lukasz's code for figuring out how to add namespace for smack. > > > > Should there be a User Namespace maintainer? > > Do you mean documented in maintainers? Yup, to make sure people know to contact you about patches that affect it. Maybe it's not needed as you're pretty on top of any changes that affect userns. And while we could document kernel/user{,_namespace}.c as affecting it, I don't know how we would describe changes outside of those files that would relate to it. So nm :) > Last I cheked I am wearing > the user namespace maintainer hat. > > Eric > > _______________________________________________ > Containers mailing list > Containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org > https://lists.linuxfoundation.org/mailman/listinfo/containers