Re: unprivileged mounts git tree

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Miklos Szeredi
Date: Thursday, September 4, 2008 - 11:03 am

On Thu, 4 Sep 2008, Serge E. Hallyn wrote:

No :)


I don't know.  It's something to think about in the future, but not
essential.  We know that without the above check the user can do bad
things: propagate mounts back into the source, and we don't want that.

We could allow binding a shared mount if

  a) the owners of the source and destination match
  b) the destination is made a slave of the source

But the current patchset doesn't allow _any_ changes to propagation
without CAP_SYS_ADMIN, so why should bind be an exception?

And yes, this is something to think about, but I think it's a rather
uncommon corner case, and so the patchset very much makes sense
without having to deal with unprivileged mount propagation changes.


No, we'd be back with the original problem.

Thanks,
Miklos
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
unprivileged mounts git tree, Miklos Szeredi, (Wed May 7, 5:05 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Aug 7, 3:27 pm)
Re: unprivileged mounts git tree, Eric W. Biederman, (Thu Aug 7, 5:07 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Aug 7, 5:25 pm)
Re: unprivileged mounts git tree, Miklos Szeredi, (Mon Aug 25, 4:01 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Wed Aug 27, 8:36 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Wed Aug 27, 8:55 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Wed Aug 27, 11:46 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Wed Sep 3, 11:45 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Wed Sep 3, 2:54 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Wed Sep 3, 3:02 pm)
Re: unprivileged mounts git tree, Miklos Szeredi, (Wed Sep 3, 3:25 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Wed Sep 3, 3:43 pm)
Re: unprivileged mounts git tree, Miklos Szeredi, (Wed Sep 3, 11:42 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 4, 6:28 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 4, 7:06 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 4, 8:40 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 4, 9:17 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 4, 10:42 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 4, 10:48 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 4, 11:03 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 4, 11:49 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 4, 3:26 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 4, 4:32 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Fri Sep 5, 8:31 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Tue Sep 9, 6:34 am)
Re: unprivileged mounts git tree, Eric W. Biederman, (Thu Sep 11, 3:37 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 11, 7:43 am)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Thu Sep 11, 8:20 am)
Re: unprivileged mounts git tree, Miklos Szeredi, (Thu Sep 11, 8:44 am)
Re: unprivileged mounts git tree, Eric W. Biederman, (Thu Sep 11, 11:54 am)
Re: unprivileged mounts git tree, Eric W. Biederman, (Thu Sep 11, 12:04 pm)
Re: unprivileged mounts git tree, Eric W. Biederman, (Thu Sep 11, 12:58 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Fri Sep 12, 3:08 pm)
Re: unprivileged mounts git tree, Eric W. Biederman, (Fri Sep 12, 8:12 pm)
Re: unprivileged mounts git tree, Serge E. Hallyn, (Sat Sep 13, 6:56 pm)<