Received: by 2002:a25:1506:0:0:0:0:0 with SMTP id 6csp793748ybv; Wed, 19 Feb 2020 09:19:28 -0800 (PST) X-Google-Smtp-Source: APXvYqzT8owPViPUX8C9NIg+QK4jgAOcSnDvpQ0qR0ofSyiPryqS6MqmL1ijvWuVZoHMGCJhSIyv X-Received: by 2002:a05:6808:98e:: with SMTP id a14mr5043849oic.8.1582132767900; Wed, 19 Feb 2020 09:19:27 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1582132767; cv=none; d=google.com; s=arc-20160816; b=a5HbXDGUCaxKSoRFqkHkO+yg09krTCz3/VC9wJ2vaKz458188rk9iOx0KkFbYi2m+G iArw9e4scFj1+kt+PKTtpeA+SiS/rVF7xeIB3Lvs0aLJEoZ88pmVQOcooUa60sK4beFZ bwpypoFhnnJxFmNWPMis7vsPh/K7o7r+lFehrZMXRt09HehbvIckzTZWr6aKlffMUnts mCAdHfawQH+BeeEnxstaIUSGzSB5tiz7VlCnKTqxTNez68BEv3nbpQoXV9jEKSFOoS7M GY9btQAJaky1MO3bGlTg6gQcYtA4m2wjbwq883rgzCoPS6LH3GtRm/N4ObWQWOh/Xwex Ogkw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=b36zkr20HdqXuvqO+MT7urMsLjmH9Hvrn+LZekExbpU=; b=oRTqQt07zuyOr2qP9ox30YjxHziDkdqhsgxiQ92cdJ+OhmItFNacOfOYKMFbJ4pjwU +/IofRpsEF2HU0okstMKKyPxRcQk4bmzKwnFU9fyhwOd5Z8Ejv0bR4+5IHd8PXz5Pys4 LhY77y8vh1h2wczLH2unnosOeoXcYGG6x4RYXj7dPjzjKspPNUK8qjMlcpnJfWA72Yvq aPbbJPZ+B6aZJ0QM7xtNeW0BE/tOwNXxe8JK4sREjoLj2YWNSpnEuJ4XFz6ef+wbdm8O Znnb50d6R6xuwa8d6cYgyKPHdAc8m5B2suQgu1nygaVHBdIPPd5lQbLXwTFm1Op917SI KXeQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=vnO2O4AR; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id y8si9541359oih.141.2020.02.19.09.19.15; Wed, 19 Feb 2020 09:19:27 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=vnO2O4AR; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726736AbgBSRTF (ORCPT + 99 others); Wed, 19 Feb 2020 12:19:05 -0500 Received: from mail.kernel.org ([198.145.29.99]:42744 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726518AbgBSRTE (ORCPT ); Wed, 19 Feb 2020 12:19:04 -0500 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 1BB072465D for ; Wed, 19 Feb 2020 17:19:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1582132744; bh=pdkNY2hNSnY9gfk2NzrHjgF6xJM4H9Y/ewvIWmreT30=; h=References:In-Reply-To:From:Date:Subject:To:Cc:From; b=vnO2O4ARZ57+m2WKOUb7GhddjqaoDXVsuMXfiNZeEGx2CUEhSrcOLwk7vQ6jehuVY 7ZAQf5jzJfdbS7ByhaI5MGieQG5Akj0KliXYRwXHNlnQNEhGb87pr//Tw8tqFq6uyH kyfrK/detgBoqWdOmwxa2BWw5+K7YNOlQZ/t1UXw= Received: by mail-wm1-f44.google.com with SMTP id c84so1514522wme.4 for ; Wed, 19 Feb 2020 09:19:04 -0800 (PST) X-Gm-Message-State: APjAAAX8loCQ14oE7f8nDpoHtcUhdqFv03xMT2dHFAJAqIatPlEvSJx/ FZKrd7XDyE/HWxicn0d1pQXh/moFzH1fk2Z6rDLxlQ== X-Received: by 2002:a1c:b0c3:: with SMTP id z186mr10898715wme.36.1582132742597; Wed, 19 Feb 2020 09:19:02 -0800 (PST) MIME-Version: 1.0 References: <20200218143411.2389182-1-christian.brauner@ubuntu.com> <20200218143411.2389182-10-christian.brauner@ubuntu.com> <20200219024233.GA19334@mail.hallyn.com> <20200219120604.vqudwaeppebvisco@wittgenstein> In-Reply-To: <20200219120604.vqudwaeppebvisco@wittgenstein> From: Andy Lutomirski Date: Wed, 19 Feb 2020 09:18:51 -0800 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: [PATCH v3 09/25] fs: add is_userns_visible() helper To: Christian Brauner Cc: "Serge E. Hallyn" , =?UTF-8?Q?St=C3=A9phane_Graber?= , "Eric W. Biederman" , Aleksa Sarai , Jann Horn , smbarber@chromium.org, Seth Forshee , Alexander Viro , Alexey Dobriyan , James Morris , Kees Cook , Jonathan Corbet , Phil Estes , LKML , Linux FS Devel , Linux Containers , LSM List , Linux API Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Feb 19, 2020 at 4:06 AM Christian Brauner wrote: > > On Tue, Feb 18, 2020 at 08:42:33PM -0600, Serge Hallyn wrote: > > On Tue, Feb 18, 2020 at 03:33:55PM +0100, Christian Brauner wrote: > > > Introduce a helper which makes it possible to detect fileystems whose > > > superblock is visible in multiple user namespace. This currently only > > > means proc and sys. Such filesystems usually have special semantics so their > > > behavior will not be changed with the introduction of fsid mappings. > > > > Hi, > > > > I'm afraid I've got a bit of a hangup about the terminology here. I > > *think* what you mean is that SB_I_USERNS_VISIBLE is an fs whose uids are > > always translated per the id mappings, not fsid mappings. But when I see > > Correct! > > > the name it seems to imply that !SB_I_USERNS_VISIBLE filesystems can't > > be seen by other namespaces at all. > > > > Am I right in my first interpretation? If so, can we talk about the > > naming? > > Yep, your first interpretation is right. What about: wants_idmaps() Maybe fsidmap_exempt()? I still haven't convinced myself that any of the above is actually correct behavior, especially when people do things like creating setuid binaries.