Dave Hansen <[email protected]> writes: > On Thu, 2006-07-13 at 21:45 -0600, Eric W. Biederman wrote: >> I think for filesystems like /proc and /sys that there will normally >> be problems. However many of those problems can be rationalized away >> as a reasonable optimization, or are not immediately apparent. > > Could you talk about some of these problems? Already mentioned but. rw permissions on sensitive files are for uid == 0. No capability checks are performed. >> Passing a file descriptor between process in a unix domain socket is >> a case where I can easily construct scenarios where there are >> indisputable problems. It is one of my standard thought experiments >> to see if a namespace is sound. > > Care to share some of those indisputable problems? Already done. Eric - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: [PATCH -mm 5/7] add user namespace
- From: Dave Hansen <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: "Serge E. Hallyn" <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- References:
- [PATCH -mm 0/7] execns syscall and user namespace
- From: Cedric Le Goater <[email protected]>
- [PATCH -mm 5/7] add user namespace
- From: Cedric Le Goater <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: [email protected] (Eric W. Biederman)
- Re: [PATCH -mm 5/7] add user namespace
- From: Cedric Le Goater <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: [email protected] (Eric W. Biederman)
- Re: [PATCH -mm 5/7] add user namespace
- From: Cedric Le Goater <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: "Serge E. Hallyn" <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: [email protected] (Eric W. Biederman)
- Re: [PATCH -mm 5/7] add user namespace
- From: Dave Hansen <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: [email protected] (Eric W. Biederman)
- Re: [PATCH -mm 5/7] add user namespace
- From: Dave Hansen <[email protected]>
- Re: [PATCH -mm 5/7] add user namespace
- From: [email protected] (Eric W. Biederman)
- Re: [PATCH -mm 5/7] add user namespace
- From: Dave Hansen <[email protected]>
- [PATCH -mm 0/7] execns syscall and user namespace
- Prev by Date: Re: [PATCH] remove volatile from x86 cmos_lock
- Next by Date: Re: [PATCH] remove volatile from nmi.c
- Previous by thread: Re: [PATCH -mm 5/7] add user namespace
- Next by thread: Re: [PATCH -mm 5/7] add user namespace
- Index(es):