login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2008
»
August
»
27
Re: unprivileged mounts git tree
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: Serge E. Hallyn
Subject:
Re: unprivileged mounts git tree
Date: Wednesday, August 27, 2008 - 11:46 am
Quoting Miklos Szeredi (
miklos@szeredi.hu
):
quoted text
> On Wed, 27 Aug 2008, Serge E. Hallyn wrote: > > Quoting Miklos Szeredi (
miklos@szeredi.hu
): > > > Serge, thanks for spotting this: it looks indeed a nasty hole! I also > > > agree about the solution. > > > > Are you implementing it, or did you want me to? > > I'll implement it.
Ok, thanks. I look forward to playing around with it when you publish the resulting git tree :)
quoted text
> > > But yeah, we should think this over very carefully. Especially > > > interaction with mount propagation, which has very complicated and > > > sometimes rather counter-intuitive semantics. > > > > I know we discussed before about whether a propagated mount from a > > non-user mount to a user mount should end up being owned by the user > > or not. I don't recall (and am not checking the code at the moment > > as your tree is sitting elsewhere) whether we mark the propagated > > tree with the right nosuid and nodev flags, or whether we call it > > a user mount or not. > > If the destination is a user mount, then > > - the propagated mount(s) will be owned by the same user as the destination > - the propagated mount(s) will inherit 'nosuid' from the destination > > I remember also thinking about 'nodev' and why it doesn't need similar > treatment to 'nosuid'. The reasoning was that 'nodev' is safe as long > as permissions are enforced, namespace shuffling cannot make it > insecure. Does that sound correct?
Yes that sounds correct, thanks for the refresher. -serge --
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
unprivileged mounts git tree
, Miklos Szeredi
, (Wed May 7, 5:05 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Aug 7, 3:27 pm)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Thu Aug 7, 5:07 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Aug 7, 5:25 pm)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Mon Aug 25, 4:01 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Wed Aug 27, 8:36 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Wed Aug 27, 8:55 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Wed Aug 27, 11:46 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Wed Sep 3, 11:45 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Wed Sep 3, 2:54 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Wed Sep 3, 3:02 pm)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Wed Sep 3, 3:25 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Wed Sep 3, 3:43 pm)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Wed Sep 3, 11:42 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 4, 6:28 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 4, 7:06 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 4, 8:40 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 4, 9:17 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 4, 10:42 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 4, 10:48 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 4, 11:03 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 4, 11:49 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 4, 3:26 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 4, 4:32 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Fri Sep 5, 8:31 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Tue Sep 9, 6:34 am)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Thu Sep 11, 3:37 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 11, 7:43 am)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Thu Sep 11, 8:20 am)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Thu Sep 11, 8:44 am)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Thu Sep 11, 11:54 am)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Thu Sep 11, 12:04 pm)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Thu Sep 11, 12:58 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Fri Sep 12, 3:08 pm)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Fri Sep 12, 8:12 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Sat Sep 13, 6:56 pm)
Re: unprivileged mounts git tree
, Eric W. Biederman
, (Sat Sep 13, 8:06 pm)
Re: unprivileged mounts git tree
, Serge E. Hallyn
, (Tue Sep 30, 12:39 pm)
Re: unprivileged mounts git tree
, Miklos Szeredi
, (Mon Oct 6, 4:05 am)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Russell King
Re: ARM defconfig files
Jesse Barnes
Re: PCI MSI breaks when booting with nosmp
James Morris
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook
Philip Langdale
[PATCH 2.6.19] mmc: Add support for SDHC cards (Take 4)
Oren Laadan
[PATCH v21 073/100] c/r: Add AF_UNIX support (v12)
git
:
Felipe Contreras
Re: [kernel.org users] [RFD] On deprecating "git-foo" for builtins
Paolo Ciarrocchi
Re: [kernel.org users] [RFD] On deprecating "git-foo" for builtins
Johannes Schindelin
[PATCH] fetch: refuse to fetch into the current branch in a non-bare repository
Johannes Schindelin
Re: [PATCH] Fix install-doc-quick target
Peter Oberndorfer
Subject: [PATCH] fix stg edit command
linux-netdev
:
Ursula Braun
[patch 2/8] [PATCH] af_iucv: sync sk shutdown flag if iucv path is quiesced
Andi Kleen
Re: RFC: Nagle latency tuning
David Miller
Re: [RFC 0/5] generic rx recycling
Gary Thomas
Re: Marvell 88E609x switch?
Chuck Lever
Re: [RFC] ipv6: Change %pI6 format to output compacted addresses?
git-commits-head
:
Linux Kernel Mailing List
New device ID for sc92031 [1088:2031]
Linux Kernel Mailing List
e1000e: Expose MDI-X status via ethtool change
Linux Kernel Mailing List
arm/imx/gpio: GPIO_INT_{HIGH,LOW}_LEV are not necessarily constant
Linux Kernel Mailing List
powerpc/kexec: Add support for FSL-BookE
Linux Kernel Mailing List
trivial: fix comment typo in fs/compat.c
openbsd-misc
:
Theo de Raadt
Re: RES: OpenBSD on IBM System X3550 7879
Bret S. Lambert
Re: any web management gui for pf ?
Rob Shepherd
x86 hardware for router system
Flickr Photo Map for iPad and iPhone
Thanks for the Great Launch of Flickr Photo Map for iPad + iPhone
Nick Holland
Re: Install OpenBSD from USB ?
Colocation donated by:
Syndicate