Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-30 Thread Serge Hallyn
Quoting Eric W. Biederman (ebied...@xmission.com): > Theodore Ts'o writes: > > > On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: > >> I forget the details, but there was another case where I wanted to > >> have the userns which 'owns' the whole fs available. I guess we'd > >> have

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-30 Thread Eric W. Biederman
Theodore Ts'o writes: > On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: >> I forget the details, but there was another case where I wanted to >> have the userns which 'owns' the whole fs available. I guess we'd >> have to check against that instead of using inode_capable. > > Yes,

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-30 Thread Eric W. Biederman
Theodore Ts'o ty...@mit.edu writes: On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: I forget the details, but there was another case where I wanted to have the userns which 'owns' the whole fs available. I guess we'd have to check against that instead of using inode_capable.

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-30 Thread Serge Hallyn
Quoting Eric W. Biederman (ebied...@xmission.com): Theodore Ts'o ty...@mit.edu writes: On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: I forget the details, but there was another case where I wanted to have the userns which 'owns' the whole fs available. I guess we'd have

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:44 PM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn >> wrote: >> > Quoting Andy Lutomirski (l...@amacapital.net): >> >> > It should be a nonissue so long as we make sure that a file owned by a >>

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn wrote: > > Quoting Andy Lutomirski (l...@amacapital.net): > >> > It should be a nonissue so long as we make sure that a file owned by a > >> > uid outside the scope of the container may not be changed

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Theodore Ts'o (ty...@mit.edu): > On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: > > I forget the details, but there was another case where I wanted to > > have the userns which 'owns' the whole fs available. I guess we'd > > have to check against that instead of using

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:32 PM, Theodore Ts'o wrote: > On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: >> I forget the details, but there was another case where I wanted to >> have the userns which 'owns' the whole fs available. I guess we'd >> have to check against that instead

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: > I forget the details, but there was another case where I wanted to > have the userns which 'owns' the whole fs available. I guess we'd > have to check against that instead of using inode_capable. Yes, that sounds right. And

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn wrote: > Quoting Andy Lutomirski (l...@amacapital.net): >> > It should be a nonissue so long as we make sure that a file owned by a >> > uid outside the scope of the container may not be changed even though >> > fs_owner_uid is set. Otherwise, it's

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On Tue, Apr 29, 2014 at 5:01 PM, Stéphane Graber wrote: > > On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: > >> On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber > >> wrote: > >> > On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): > On 04/29/2014 03:29 PM, Serge Hallyn wrote: > > Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): > >> On 04/30/2014 01:02 AM, Serge Hallyn wrote: > >>> Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): > On 04/29/2014 09:52 PM,

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:10 PM, Marian Marinov wrote: > On 04/30/2014 03:01 AM, Stéphane Graber wrote: >> >> On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: >>> >>> On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber >>> wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700,

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:01 PM, Stéphane Graber wrote: > On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: >> On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber wrote: >> > On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: >> >> On Tue, Apr 29, 2014 at 4:20 PM,

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 03:01 AM, Stéphane Graber wrote: On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov wrote: On

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Stéphane Graber
On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: > On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber wrote: > > On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: > >> On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov wrote: > >> > On 04/30/2014 01:45 AM, Andy

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Stéphane Graber
On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: > On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov wrote: > > On 04/30/2014 01:45 AM, Andy Lutomirski wrote: > >> > >> On 04/29/2014 03:29 PM, Serge Hallyn wrote: > >>> > >>> Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org):

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber wrote: > On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: >> On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov wrote: >> > On 04/30/2014 01:45 AM, Andy Lutomirski wrote: >> >> >> >> On 04/29/2014 03:29 PM, Serge Hallyn wrote: >> >>>

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov wrote: > On 04/30/2014 01:45 AM, Andy Lutomirski wrote: >> >> On 04/29/2014 03:29 PM, Serge Hallyn wrote: >>> >>> Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: > > Quoting

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 01:45 AM, Andy Lutomirski wrote: On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/29/2014 09:52 PM, Serge Hallyn

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:06 PM, Theodore Ts'o wrote: > On Tue, Apr 29, 2014 at 03:45:24PM -0700, Andy Lutomirski wrote: >> >> Wait, what? >> >> Inodes aren't owned by user namespaces; they're owned by users. And any >> user can arrange to have a user namespace in which they pass an >>

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Tue, Apr 29, 2014 at 03:45:24PM -0700, Andy Lutomirski wrote: > > Wait, what? > > Inodes aren't owned by user namespaces; they're owned by users. And any > user can arrange to have a user namespace in which they pass an > inode_capable check on any inode that they own. > > Presumably

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On 04/29/2014 03:29 PM, Serge Hallyn wrote: > Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): >> On 04/30/2014 01:02 AM, Serge Hallyn wrote: >>> Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/29/2014 09:52 PM, Serge Hallyn wrote: > Quoting Theodore Ts'o

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Marian Marinov (m...@1h.com): > On 04/30/2014 01:02 AM, Serge Hallyn wrote: > >Quoting Marian Marinov (m...@1h.com): > >>On 04/29/2014 09:52 PM, Serge Hallyn wrote: > >>>Quoting Theodore Ts'o (ty...@mit.edu): > On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: > > >

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (m...@1h.com): On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Marian Marinov (m...@1h.com): > On 04/29/2014 09:52 PM, Serge Hallyn wrote: > >Quoting Theodore Ts'o (ty...@mit.edu): > >>On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: > >>> > >>>I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) > >>>check with

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) check with ns_capable(current_cred()->user_ns, CAP_LINUX_IMMUTABLE).

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Theodore Ts'o (ty...@mit.edu): > On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: > > > > I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) > > check with ns_capable(current_cred()->user_ns, CAP_LINUX_IMMUTABLE). > > Um, wouldn't it be better to

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: > > I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) > check with ns_capable(current_cred()->user_ns, CAP_LINUX_IMMUTABLE). Um, wouldn't it be better to simply fix the capable() function? /** * capable -

ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
Hello, when using user namespaces I found a bug in the capability checks done by ioctl. If someone tries to use chattr +i while in a different user namespace it will get the following: ioctl(3, EXT2_IOC_SETFLAGS, 0x7fffa4fedacc) = -1 EPERM (Operation not permitted) I'm proposing a fix to

ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
Hello, when using user namespaces I found a bug in the capability checks done by ioctl. If someone tries to use chattr +i while in a different user namespace it will get the following: ioctl(3, EXT2_IOC_SETFLAGS, 0x7fffa4fedacc) = -1 EPERM (Operation not permitted) I'm proposing a fix to

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) check with ns_capable(current_cred()-user_ns, CAP_LINUX_IMMUTABLE). Um, wouldn't it be better to simply fix the capable() function? /** * capable -

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) check with ns_capable(current_cred()-user_ns, CAP_LINUX_IMMUTABLE). Um, wouldn't it be better to simply fix

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) check with ns_capable(current_cred()-user_ns, CAP_LINUX_IMMUTABLE).

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Marian Marinov (m...@1h.com): On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the capable(CAP_LINUX_IMMUTABLE) check with

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (m...@1h.com): On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to this, by replacing the

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Marian Marinov (m...@1h.com): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (m...@1h.com): On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o (ty...@mit.edu): On Tue, Apr 29, 2014 at 04:49:14PM +0300, Marian Marinov wrote: I'm proposing a fix to

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/29/2014 09:52 PM, Serge Hallyn wrote: Quoting Theodore Ts'o

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Tue, Apr 29, 2014 at 03:45:24PM -0700, Andy Lutomirski wrote: Wait, what? Inodes aren't owned by user namespaces; they're owned by users. And any user can arrange to have a user namespace in which they pass an inode_capable check on any inode that they own. Presumably there's a

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:06 PM, Theodore Ts'o ty...@mit.edu wrote: On Tue, Apr 29, 2014 at 03:45:24PM -0700, Andy Lutomirski wrote: Wait, what? Inodes aren't owned by user namespaces; they're owned by users. And any user can arrange to have a user namespace in which they pass an

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 01:45 AM, Andy Lutomirski wrote: On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/29/2014 09:52 PM, Serge Hallyn

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov m...@1h.com wrote: On 04/30/2014 01:45 AM, Andy Lutomirski wrote: On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov m...@1h.com wrote: On 04/30/2014 01:45 AM, Andy Lutomirski wrote: On 04/29/2014 03:29 PM, Serge

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Stéphane Graber
On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov m...@1h.com wrote: On 04/30/2014 01:45 AM, Andy Lutomirski wrote: On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Stéphane Graber
On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:20 PM, Marian Marinov m...@1h.com wrote: On 04/30/2014

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Marian Marinov
On 04/30/2014 03:01 AM, Stéphane Graber wrote: On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:20 PM, Marian

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:01 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:22:55PM -0700, Andy Lutomirski wrote: On Tue,

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:10 PM, Marian Marinov m...@1h.com wrote: On 04/30/2014 03:01 AM, Stéphane Graber wrote: On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:22:55PM

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): On 04/29/2014 03:29 PM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/30/2014 01:02 AM, Serge Hallyn wrote: Quoting Marian Marinov (mm-108mbtlg...@public.gmane.org): On 04/29/2014 09:52 PM, Serge Hallyn

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): On Tue, Apr 29, 2014 at 5:01 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at 04:51:54PM -0700, Andy Lutomirski wrote: On Tue, Apr 29, 2014 at 4:47 PM, Stéphane Graber stgra...@ubuntu.com wrote: On Tue, Apr 29, 2014 at

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn serge.hal...@ubuntu.com wrote: Quoting Andy Lutomirski (l...@amacapital.net): It should be a nonissue so long as we make sure that a file owned by a uid outside the scope of the container may not be changed even though fs_owner_uid is set.

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Theodore Ts'o
On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: I forget the details, but there was another case where I wanted to have the userns which 'owns' the whole fs available. I guess we'd have to check against that instead of using inode_capable. Yes, that sounds right. And *please*

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:32 PM, Theodore Ts'o ty...@mit.edu wrote: On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: I forget the details, but there was another case where I wanted to have the userns which 'owns' the whole fs available. I guess we'd have to check against that

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Theodore Ts'o (ty...@mit.edu): On Wed, Apr 30, 2014 at 12:16:41AM +, Serge Hallyn wrote: I forget the details, but there was another case where I wanted to have the userns which 'owns' the whole fs available. I guess we'd have to check against that instead of using

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Serge Hallyn
Quoting Andy Lutomirski (l...@amacapital.net): On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn serge.hal...@ubuntu.com wrote: Quoting Andy Lutomirski (l...@amacapital.net): It should be a nonissue so long as we make sure that a file owned by a uid outside the scope of the container may not

Re: ioctl CAP_LINUX_IMMUTABLE is checked in the wrong namespace

2014-04-29 Thread Andy Lutomirski
On Tue, Apr 29, 2014 at 5:44 PM, Serge Hallyn serge.hal...@ubuntu.com wrote: Quoting Andy Lutomirski (l...@amacapital.net): On Tue, Apr 29, 2014 at 5:21 PM, Serge Hallyn serge.hal...@ubuntu.com wrote: Quoting Andy Lutomirski (l...@amacapital.net): It should be a nonissue so long as we