From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from out02.mta.xmission.com ([166.70.13.232]:45856 "EHLO out02.mta.xmission.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1030888AbeEXQpa (ORCPT ); Thu, 24 May 2018 12:45:30 -0400 From: ebiederm@xmission.com (Eric W. Biederman) To: Christian Brauner Cc: Linux Containers , linux-kernel@vger.kernel.org, Seth Forshee , linux-fsdevel@vger.kernel.org References: <87o9h6554f.fsf@xmission.com> <20180523232538.4880-4-ebiederm@xmission.com> <20180524155803.GB19932@mailbox.org> Date: Thu, 24 May 2018 11:45:06 -0500 In-Reply-To: <20180524155803.GB19932@mailbox.org> (Christian Brauner's message of "Thu, 24 May 2018 17:58:03 +0200") Message-ID: <87603d3svh.fsf@xmission.com> MIME-Version: 1.0 Content-Type: text/plain Subject: Re: [REVIEW][PATCH 4/6] fs: Allow superblock owner to access do_remount_sb() Sender: linux-fsdevel-owner@vger.kernel.org List-ID: Christian Brauner writes: > On Wed, May 23, 2018 at 06:25:36PM -0500, Eric W. Biederman wrote: >> Superblock level remounts are currently restricted to global >> CAP_SYS_ADMIN, as is the path for changing the root mount to >> read only on umount. Loosen both of these permission checks to >> also allow CAP_SYS_ADMIN in any namespace which is privileged >> towards the userns which originally mounted the filesystem. > > Acked-by: Christian Brauner > >> >> Signed-off-by: Seth Forshee >> Acked-by: "Eric W. Biederman" >> Acked-by: Serge Hallyn > > Note, I just talked to Serge. This should be Acked-by: Serge Hallyn Now you know how long these patches have been sitting waiting to get merged. Eric