netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Michał Mirosław" <mirqus@gmail.com>
To: C Anthony Risinger <anthony@xtfx.me>
Cc: "Serge E. Hallyn" <serge@hallyn.com>,
	"Eric W. Biederman" <ebiederm@xmission.com>,
	Linux Containers <containers@lists.osdl.org>,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [GIT PULL] Namespace file descriptors for 2.6.40
Date: Thu, 26 May 2011 00:11:25 +0200	[thread overview]
Message-ID: <BANLkTinPTRxmCPhsrqq9fr1veqiNgns_zQ@mail.gmail.com> (raw)
In-Reply-To: <BANLkTinbw6pZjhMscfXFMArd=XU=VC=+eQ@mail.gmail.com>

2011/5/25 C Anthony Risinger <anthony@xtfx.me>:
> On Wed, May 25, 2011 at 4:38 PM, Serge E. Hallyn <serge@hallyn.com> wrote:
>> Quoting C Anthony Risinger (anthony@xtfx.me):
[...]
>>> if i understand correctly, mount namespaces (for example), allow one
>>> to build such constructs as "private /tmp" and similar that even
>>> `root` cannot access ... and there are many reasons `root` does not
>>> deserve to completely know/interact with user processes (FUSE makes a
>>> good example ... just because i [user] have SSH access to a machine,
>>> why should `root`?)
>> If for instance you have a file open in your private /tmp, then root
>> in another mounts ns can open the file through /proc/$$/fd/N anyway.
>> If it's a directory, he can now traverse the whole fs.
> aaah right :-( ... there's always another way isn't there ... curse
> you Linux for being so flexible! (just kidding baby i love you)
>
> this seems like a more fundamental issue then?  or should i not expect
> to be able to achieve separation like this?  i ask in the context of
> OS virt via cgroups + namespaces, eg. LXC et al, because i'm about to
> perform a massive overhaul to our crusty sub-2.6.18 infrastructure and
> i've used/followed these technologies for couple years now ... and
> it's starting to feel like "the right time".

You either trust the admin or don't use the machine. There is no third way.

Best Regards,
Michał Mirosław

  reply	other threads:[~2011-05-25 22:11 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-05-23 21:05 [GIT PULL] Namespace file descriptors for 2.6.40 Eric W. Biederman
2011-05-25 21:05 ` C Anthony Risinger
2011-05-25 21:38   ` Serge E. Hallyn
2011-05-25 21:55     ` C Anthony Risinger
2011-05-25 22:11       ` Michał Mirosław [this message]
2011-05-25 23:40       ` Eric W. Biederman
2011-05-27 20:18         ` C Anthony Risinger
  -- strict thread matches above, loose matches on Subject: below --
2011-05-21 23:39 Eric W. Biederman
2011-05-21 23:42 ` Linus Torvalds
2011-05-22  0:33   ` Eric W. Biederman
     [not found]     ` <m1boyvpo9r.fsf-+imSwln9KH6u2/kzUuoCbdi2O/JbrIOy@public.gmane.org>
2011-05-22  7:13       ` James Bottomley
2011-05-22  8:42         ` Ingo Molnar
2011-05-24  7:03           ` Eric W. Biederman
2011-05-24  7:16             ` Ingo Molnar
2011-05-25  0:34               ` Valdis.Kletnieks
2011-05-25  8:25                 ` Ingo Molnar
2011-05-25  8:35                   ` Geert Uytterhoeven
2011-05-25 12:47                     ` Ingo Molnar
2011-05-25 13:00                       ` Geert Uytterhoeven
2011-05-25 13:17                         ` Ingo Molnar
2011-05-25 15:22                           ` Geert Uytterhoeven
2011-05-24  7:26             ` James Bottomley
2011-05-24  8:11               ` Eric W. Biederman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=BANLkTinPTRxmCPhsrqq9fr1veqiNgns_zQ@mail.gmail.com \
    --to=mirqus@gmail.com \
    --cc=anthony@xtfx.me \
    --cc=containers@lists.osdl.org \
    --cc=ebiederm@xmission.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=serge@hallyn.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).