Thread (49 messages) 49 messages, 11 authors, 2019-02-21

Re: [RFC PATCH 09/27] vfs: Allow mounting to other namespaces

From: Al Viro <viro@zeniv.linux.org.uk>
Date: 2019-02-17 00:14:49
Also in: keyrings, linux-cifs, linux-fsdevel, linux-nfs, lkml

On Fri, Feb 15, 2019 at 04:08:46PM +0000, David Howells wrote:
Currently sys_move_mount() and sys_mount(MS_MOVE) prevent the caller from
moving a mount into a namespace not their own.  Relax this such that any
mount can be mounted onto any given mountpoint provided that the source
mount is either detached or the same namespace as the destination.

This permits container namespaces to be built from the outside rather than
from the inside.
I'm looking forward to your analysis of security implications, as well as
the proof that attach_recursive_mnt() won't get confused by that...
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help