Re: [PATCH] devpts: Add ptmx_uid and ptmx_gid options
- From: Alexander Larsson <alexl redhat com>
- To: Andy Lutomirski <luto amacapital net>, "Eric W. Biederman" <ebiederm xmission com>
- Cc: gnome-os-list gnome org, Linux Containers <containers lists linux-foundation org>, "linux-kernel vger kernel org" <linux-kernel vger kernel org>, James Bottomley <James Bottomley hansenpartnership com>, mclasen redhat com, Linux FS Devel <linux-fsdevel vger kernel org>
- Subject: Re: [PATCH] devpts: Add ptmx_uid and ptmx_gid options
- Date: Tue, 08 Mar 2016 10:16:31 +0100
On mån, 2016-03-07 at 20:59 -0800, Andy Lutomirski wrote:
On Thu, May 28, 2015 at 12:42 PM, Eric W. Biederman
<ebiederm xmission com> wrote:
Andy Lutomirski <luto amacapital net> writes:
Apparently alexl is encountering some annoyances related to the
current workaround, and the workaround is certainly ugly.
It works, but it introduces an extra namespace that gets exposed to the
world, which is pretty ugly. For instance, entering the namespace
becomes hard. I can setns() into the intermediate user+mount namespace
without problems, but if i try to setns into the final user+mount ns
(it gets its own implicit mount ns) i get EPERM. I'm not sure exactly
why though...
Your proposal seems like it could break some use cases involving
fscaps on a mount or mount-like binary.
What if we change it to use the owner of the userns that owns the
current mount ns? For anything that doesn't explicitly use
namespaces, this will be zero. For namespace users, it should do the
right thing.
Any of these is fine with me. One nice thing would if i could somehow
detect whether this was supported or not so that i can fall back on the
old workaround.
--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Alexander Larsson Red Hat, Inc
alexl redhat com alexander larsson gmail com
He's an all-American guitar-strumming househusband with no name. She's a
scantily clad impetuous former first lady who don't take no shit from
nobody. They fight crime!
[
Date Prev][
Date Next] [
Thread Prev][
Thread Next]
[
Thread Index]
[
Date Index]
[
Author Index]