Re: [PATCH 2/8] user_ns: Introduce user_nsmap_uid and user_ns_map_gid.

2 messages, 2 authors, 2010-06-15 · open the first message on its own page

Re: [PATCH 2/8] user_ns: Introduce user_nsmap_uid and user_ns_map_gid.

From: Pavel Emelyanov <hidden>
Date: 2010-06-15 08:02:17

On 06/13/2010 05:28 PM, Eric W. Biederman wrote:
Define what happens when a we view a uid from one user_namespace
in another user_namepece.

- If the user namespaces are the same no mapping is necessary.

- For most cases of difference use overflowuid and overflowgid,
  the uid and gid currently used for 16bit apis when we have a 32bit uid
  that does fit in 16bits.  Effectively the situation is the same,
  we want to return a uid or gid that is not assigned to any user.

- For the case when we happen to be mapping the uid or gid of the
  creator of the target user namespace use uid 0 and gid as confusing
  that user with root is not a problem.

Signed-off-by: Eric W. Biederman <ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
I suppose this one should go via Andrew, not Dave.

Anyway, Acked-by: Pavel Emelyanov [off-list ref]

Re: [PATCH 2/8] user_ns: Introduce user_nsmap_uid and user_ns_map_gid.

From: Eric W. Biederman <hidden>
Date: 2010-06-15 22:38:00

Pavel Emelyanov [off-list ref] writes:
On 06/13/2010 05:28 PM, Eric W. Biederman wrote:
quoted
Define what happens when a we view a uid from one user_namespace
in another user_namepece.

- If the user namespaces are the same no mapping is necessary.

- For most cases of difference use overflowuid and overflowgid,
  the uid and gid currently used for 16bit apis when we have a 32bit uid
  that does fit in 16bits.  Effectively the situation is the same,
  we want to return a uid or gid that is not assigned to any user.

- For the case when we happen to be mapping the uid or gid of the
  creator of the target user namespace use uid 0 and gid as confusing
  that user with root is not a problem.

Signed-off-by: Eric W. Biederman <redacted>
I suppose this one should go via Andrew, not Dave.
If it was stand alone I would send it that way.

In this case I'm hope Dave will indulge me because this bit is
simple, the only user for now is the network stack, and the people
maintaining the code have already acked the patch.

Eric
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help