linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* LXC+overlayfs in unprivileged mode
@ 2016-12-31 17:42 Linas Vepstas
  2017-01-01  8:51 ` Amir Goldstein
  0 siblings, 1 reply; 7+ messages in thread
From: Linas Vepstas @ 2016-12-31 17:42 UTC (permalink / raw)
  To: Miklos Szeredi, linux-unionfs, linux-fsdevel, Amir Goldstein,
	Vivek Goyal

Hi,

I tripped across an LXC bug that actually appears to be an overlayfs
security feature (maybe) and was wondering how to clarify the status
of the code. Apparently, Ubuntu is carrying patches that enable this
function, and so the question is if these or something more appropriate
can be pulled into the mainline kernel or into overlayfs (or perhaps they
have been already; the situation is confusing).

The issue is that LXC+overlayfs seems to not work in an unprivileged
container. A more detailed description, with a particularly simple test
case is given in https://github.com/lxc/lxc/issues/1370#issuecomment269845311
Based on searches through google, it seems likely that the reason it
does not work is due to one or more privilege-escalation exploits,
except that these may or may not be patched already... thus this email.

Any advice on how to proceed?

--linas

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2017-01-04 13:49 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-12-31 17:42 LXC+overlayfs in unprivileged mode Linas Vepstas
2017-01-01  8:51 ` Amir Goldstein
2017-01-01 20:32   ` Linas Vepstas
2017-01-03 13:48     ` Vivek Goyal
2017-01-03 16:08       ` Linas Vepstas
2017-01-04 13:49         ` Vivek Goyal
2017-01-03 23:47       ` Eric W. Biederman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).