Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-17 Thread Serge Hallyn
Quoting Eric W. Biederman (ebied...@xmission.com): > "Serge E. Hallyn" writes: > > > I'm not "relying on LSM" to make these safe. I'm relying on the > > uid mappings to make these safe. > > > > Nevertheless I at least have hope of working around the others (in a > > distro-acceptable way), so if

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Eric W. Biederman
"Serge E. Hallyn" writes: > I'm not "relying on LSM" to make these safe. I'm relying on the > uid mappings to make these safe. > > Nevertheless I at least have hope of working around the others (in a > distro-acceptable way), so if the others are too scary I'll pursue > the workaround for the ot

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Tue, Jul 16, 2013 at 3:03 PM, Serge E. Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On Tue, Jul 16, 2013 at 2:37 PM, Serge E. Hallyn wrote: > >> > Quoting Andy Lutomirski (l...@amacapital.net): > >> >> On 07/16/2013 12:5

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Andy Lutomirski
On Tue, Jul 16, 2013 at 3:03 PM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Tue, Jul 16, 2013 at 2:37 PM, Serge E. Hallyn wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: >> >> > Quoting Al Viro (v..

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Tue, Jul 16, 2013 at 2:37 PM, Serge E. Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: > >> > Quoting Al Viro (v...@zeniv.linux.org.uk): > >> >> On Tue, Jul 16, 2013 at 02:29:20

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Andy Lutomirski
On Tue, Jul 16, 2013 at 2:37 PM, Serge E. Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: >> > Quoting Al Viro (v...@zeniv.linux.org.uk): >> >> On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: >> >>> All the files will b

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Serge E. Hallyn
Quoting Serge E. Hallyn (se...@hallyn.com): > Quoting Andy Lutomirski (l...@amacapital.net): > > On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: > > > Quoting Al Viro (v...@zeniv.linux.org.uk): > > >> On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: > > >>> All the files will be owned b

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Serge E. Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: > > Quoting Al Viro (v...@zeniv.linux.org.uk): > >> On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: > >>> All the files will be owned by host root, so there's no security > >>> concern in a

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Andy Lutomirski
On 07/16/2013 12:50 PM, Serge E. Hallyn wrote: > Quoting Al Viro (v...@zeniv.linux.org.uk): >> On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: >>> All the files will be owned by host root, so there's no security >>> concern in allowing this. >> >> Files owned by root != very bad thing

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Serge E. Hallyn
Quoting Al Viro (v...@zeniv.linux.org.uk): > On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: > > All the files will be owned by host root, so there's no security > > concern in allowing this. > > Files owned by root != very bad things can't be done by non-root. > Especially for debug

Re: [PATCH RFC] allow some kernel filesystems to be mounted in a user namespace

2013-07-16 Thread Al Viro
On Tue, Jul 16, 2013 at 02:29:20PM -0500, Serge Hallyn wrote: > All the files will be owned by host root, so there's no security > concern in allowing this. Files owned by root != very bad things can't be done by non-root. Especially for debugfs, which is very much a "don't even think about mounti