linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Christoph Hellwig <hch@infradead.org>
To: Aleksa Sarai <cyphar@cyphar.com>
Cc: Miklos Szeredi <miklos@szeredi.hu>,
	Christoph Hellwig <hch@infradead.org>,
	Christian Brauner <brauner@kernel.org>, Jan Kara <jack@suse.cz>,
	Alexander Viro <viro@zeniv.linux.org.uk>,
	Chuck Lever <chuck.lever@oracle.com>,
	Jeff Layton <jlayton@kernel.org>,
	Amir Goldstein <amir73il@gmail.com>,
	Alexander Aring <alex.aring@gmail.com>,
	linux-fsdevel@vger.kernel.org, linux-nfs@vger.kernel.org,
	linux-kernel@vger.kernel.org, linux-api@vger.kernel.org
Subject: Re: [PATCH RFC v2] fhandle: expose u64 mount id to name_to_handle_at(2)
Date: Mon, 3 Jun 2024 22:22:22 -0700	[thread overview]
Message-ID: <Zl6kjsiGl0pm-p-o@infradead.org> (raw)
In-Reply-To: <20240529.013815-fishy.value.nervous.brutes-FzobWXrzoo2@cyphar.com>

On Sat, Jun 01, 2024 at 01:12:31AM -0700, Aleksa Sarai wrote:
> Not to mention that providing a mount fd is what allows for extensions
> like Christian's proposed method of allowing restricted forms of
> open_by_handle_at() to be used by unprivileged users.

As mentioned there I find the concept of an unprivileged
open_by_handle_at extremely questionable as it trivially gives access to
any inode on the file systems.

> If file handles really are going to end up being the "correct" mechanism
> of referencing inodes by userspace,

They aren't.

> then future API designs really need
> to stop assuming that the user is capable(CAP_DAC_READ_SEARCH).

There is no way to support open by handle for unprivileged users.  The
concept of an inode number based file handle simply does not work for
that at all.


  parent reply	other threads:[~2024-06-04  5:22 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-05-23 20:57 [PATCH RFC v2] fhandle: expose u64 mount id to name_to_handle_at(2) Aleksa Sarai
2024-05-24  4:58 ` Amir Goldstein
2024-05-26  9:25 ` Christoph Hellwig
2024-05-26 19:01   ` Aleksa Sarai
2024-05-27 11:47     ` Christoph Hellwig
2024-05-27 12:29       ` Christian Brauner
2024-05-27 13:17         ` Christian Brauner
2024-05-27 15:47           ` Trond Myklebust
2024-05-28  7:05             ` Christian Brauner
2024-05-27 16:18         ` Christoph Hellwig
2024-05-27 13:34       ` Jan Kara
2024-05-27 16:24         ` Christoph Hellwig
2024-05-28  8:20           ` Christian Brauner
2024-05-28  8:28             ` Christoph Hellwig
2024-05-28  9:17               ` Christian Brauner
2024-05-28 10:55                 ` Christoph Hellwig
2024-05-28 12:04                   ` Christian Brauner
2024-05-28 13:22                     ` Christoph Hellwig
2024-05-28 13:28                       ` Miklos Szeredi
2024-05-29  6:34                         ` Christoph Hellwig
2024-06-01  8:12                         ` Aleksa Sarai
2024-06-03 10:30                           ` Jan Kara
2024-06-04  5:22                           ` Christoph Hellwig [this message]
2024-05-29  7:40                       ` Christian Brauner
2024-05-31  8:14                         ` Christoph Hellwig
2024-05-31 10:28                           ` Christian Brauner
2024-05-26 22:32   ` Trond Myklebust
2024-05-27 11:49     ` hch
2024-05-27 15:38       ` Trond Myklebust
2024-05-27 16:29         ` hch
2024-05-28  7:12           ` Christian Brauner
2024-05-28  7:15             ` hch
2024-05-28 10:11           ` Jan Kara
2024-05-28 10:56             ` hch
2024-05-28 23:25               ` Dave Chinner
2024-05-29  6:24                 ` hch
2024-05-29  7:23                   ` Amir Goldstein
2024-05-27 12:22   ` Christian Brauner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Zl6kjsiGl0pm-p-o@infradead.org \
    --to=hch@infradead.org \
    --cc=alex.aring@gmail.com \
    --cc=amir73il@gmail.com \
    --cc=brauner@kernel.org \
    --cc=chuck.lever@oracle.com \
    --cc=cyphar@cyphar.com \
    --cc=jack@suse.cz \
    --cc=jlayton@kernel.org \
    --cc=linux-api@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nfs@vger.kernel.org \
    --cc=miklos@szeredi.hu \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).