From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932631AbbJIDoR (ORCPT ); Thu, 8 Oct 2015 23:44:17 -0400 Received: from mail113-249.mail.alibaba.com ([205.204.113.249]:41227 "EHLO us-alimail-mta2.hst.scl.en.alidc.net" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S932153AbbJIDoQ (ORCPT ); Thu, 8 Oct 2015 23:44:16 -0400 X-Alimail-AntiSpam: AC=PASS;BC=-1|-1;BR=01201311R181e4;FP=0|-1|-1|-1|0|-1|-1|-1;HT=e02c03307;MF=hillf.zj@alibaba-inc.com;NM=1;PH=DS;RN=6;SR=0; Reply-To: "Hillf Danton" From: "Hillf Danton" To: "'Sergei Zviagintsev'" Cc: "Greg Kroah-Hartman" , "'Daniel Mack'" , "'David Herrmann'" , "'Djalal Harouni'" , "linux-kernel" Subject: Re: [PATCH 07/44] kdbus: Fix comment on translation of caps between namespaces Date: Fri, 09 Oct 2015 11:43:22 +0800 Message-ID: <05ec01d10244$a5bddc10$f1399430$@alibaba-inc.com> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Mailer: Microsoft Outlook 14.0 Thread-Index: AdECQ+Spw5/knFtyR0KYdXmStzCT6Q== Content-Language: zh-cn Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org > @@ -730,15 +730,21 @@ static void kdbus_meta_export_caps(struct kdbus_meta_caps *out, > > /* > * This translates the effective capabilities of 'cred' into the given > - * user-namespace. If the given user-namespace is a child-namespace of > - * the user-namespace of 'cred', the mask can be copied verbatim. If > - * not, the mask is cleared. > - * There's one exception: If 'cred' is the owner of any user-namespace > - * in the path between the given user-namespace and the user-namespace > - * of 'cred', then it has all effective capabilities set. This means, > - * the user who created a user-namespace always has all effective > - * capabilities in any child namespaces. Note that this is based on the > - * uid of the namespace creator, not the task hierarchy. > + * user namespace according to the following rules: > + * > + * - If 'cred' is a member of the given user namespace or any of its > + * parent user namespaces, the mask is copied verbatim. That is, if Clearer/Better if "if not, the mask is cleared." is reserved. > + * a process has a capability in a user namespace, then it has it in > + * all child user namespaces too. > + * > + * - If the effective UID of 'cred' matches the owner of the given user > + * namespace or any of its parent user namespaces and 'cred' itself > + * resides in the parent of that user namespace which it owns, then > + * it has all effective capabilities set. This means that the user > + * who created a user namespace always has all effective capabilities > + * in all child namespaces while staying in the parent of the user > + * namespace which it owns. Note that this is based on the UID of the > + * namespace creator, not the task hierarchy. > */ > for (iter = user_ns; iter; iter = iter->parent) { > if (iter == cred->user_ns) { > -- > 1.8.3.1 >