summaryrefslogtreecommitdiffstats
path: root/Documentation
diff options
context:
space:
mode:
authorEric W. Biederman <ebiederm@xmission.com>2013-03-13 11:51:49 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2013-03-13 15:00:20 -0700
commite66eded8309ebf679d3d3c1f5820d1f2ca332c71 (patch)
tree768e1d799f6d6a4a7f85f48d9e9fc431dc8d017c /Documentation
parent6c23cbbd5056b155401b0a2b5567d530e6c750c4 (diff)
downloadop-kernel-dev-e66eded8309ebf679d3d3c1f5820d1f2ca332c71.zip
op-kernel-dev-e66eded8309ebf679d3d3c1f5820d1f2ca332c71.tar.gz
userns: Don't allow CLONE_NEWUSER | CLONE_FS
Don't allowing sharing the root directory with processes in a different user namespace. There doesn't seem to be any point, and to allow it would require the overhead of putting a user namespace reference in fs_struct (for permission checks) and incrementing that reference count on practically every call to fork. So just perform the inexpensive test of forbidding sharing fs_struct acrosss processes in different user namespaces. We already disallow other forms of threading when unsharing a user namespace so this should be no real burden in practice. This updates setns, clone, and unshare to disallow multiple user namespaces sharing an fs_struct. Cc: stable@vger.kernel.org Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Diffstat (limited to 'Documentation')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud