Thread (4 messages) flat view 4 messages, 3 authors, 2016-07-26

Re: [PATCH v2 00/10] userns: sysctl limits for namespaces

From: Michael Kerrisk (man-pages) <hidden>
Date: 2016-07-26 17:29:02
Also in: linux-api, linux-fsdevel, lkml

On 26 July 2016 at 18:52, Kees Cook [off-list ref] wrote:
On Tue, Jul 26, 2016 at 8:06 AM, Eric W. Biederman
[off-list ref] wrote:
quoted
"Michael Kerrisk (man-pages)" [off-list ref] writes:
quoted
Hello Eric,

I realized I had a question after the last mail.

On 07/21/2016 06:39 PM, Eric W. Biederman wrote:
quoted
This patchset addresses two use cases:
- Implement a sane upper bound on the number of namespaces.
- Provide a way for sandboxes to limit the attack surface from
  namespaces.
Can you say more about the second point? What exactly is the
problem that is being addressed, and how does the patch series
address it? (It would be good to have those details in the
revised commit message...)
At some point it was reported that seccomp was not sufficient to disable
namespace creation.  I need to go back and look at that claim to see
which set of circumstances that was referring to.  Seccomp doesn't stack
so I can see why it is an issue.
seccomp does stack. The trouble usually comes from a perception that
seccomp overhead is not trivial, so setting a system-wide policy is a
bit of a large hammer for such a limitiation. Also, at the time,
seccomp could be bypasses with ptrace, but this (as of v4.8) is no
longer true.
Sounds like someone needs to send me a patch for the seccomp.2 man page?

Cheers,

Michael

-- 
Michael Kerrisk
Linux man-pages maintainer; http://www.kernel.org/doc/man-pages/
Linux/UNIX System Programming Training: http://man7.org/training/
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help