Received: by 2002:a05:7412:cfc7:b0:fc:a2b0:25d7 with SMTP id by7csp2075980rdb; Tue, 20 Feb 2024 17:02:13 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCXuh/nzCeYjQLIsF41nM/Bga6JMoWBSNjWJXRnXMQNL5RaRWFVx4YOslXvgmHmMG2fNTXI1KQ6ib+Ch5EKOItr3Q2n/uRDEg3TlaUTRYw== X-Google-Smtp-Source: AGHT+IHVyL5fBzCQPWQUy+FYln5PiSpLxMsyZRzn9ACyg4R0VmvkGrjDY0vzGzQjEZpJKWIyeyO4 X-Received: by 2002:a6b:c8c4:0:b0:7c3:f3e4:8ed9 with SMTP id y187-20020a6bc8c4000000b007c3f3e48ed9mr19738680iof.6.1708477333126; Tue, 20 Feb 2024 17:02:13 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1708477333; cv=pass; d=google.com; s=arc-20160816; b=LrCjdp22yRTNhK1Fg8LRyCCrDq+OOYYKKInXk+h8tS3LGFvkKaulvcz/KoL0vl6QJB 5lvJDqePtY5vpzb/XeUVySSJ/pNUquBtE0jWkwL3NRL4jq+xr27sK22M6scNbeGJERNA wAIW42lC7EkT86kqTQ3m3N+eSgRY4KJdt3PSKA+g4bSnYS6i181pARkDI+tvKsWKn8tH 7TbNYZWpTSac0lLIC92nemo6UmbEO1FKbDu7Xu2WsJlskqY1+B1KOgSInKVuPW4PH7zR tpiroLSGQRpWXPTK6uV9Opf1XndxagmYzgPj84aoId+jK2cahC07pZPLUhHATcClKDBo SLWw== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:list-unsubscribe:list-subscribe:list-id:precedence :references:message-id:subject:cc:to:from:dkim-signature:date; bh=gVSQ1AUX97J8Bh4kyQx7tym/UpGwt+ikMSltFXfe7fU=; fh=AUzoeZh3VRMrSohLmmU/UfBAwasK3c5pdBKI7A/BAhI=; b=IirAyuTDhccexBBqb1ArN4pLaQygPvVr42Nr7Mnc4NW4X8t1kSVelRrDhDghC435fk pcFSASEoiJyosvuin2LSZgwoHKVRiI+H2V77RtFhd93hF2KHrhFOALjQW4oNoZTgLYbG yQ/dWn8UeACVYIiDhsZEMH/lh5nJR3cFDgzfw05zV1kNNRcJicm+bOv2a84XATUiQ/j/ 1B2NlZ+l1E+jrX8wsesTbGToKrfziwv/iiklKDQCuqr3DAP+oJm/oM7cViJUgCaz/MFu rPEDU7xfbCx52/79V+Pxl0vdzeR3EigJ39qm6LaGls0rJ2cUzvr35Cp6zA40nsIZfPP3 /pFw==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@linux.dev header.s=key1 header.b=BlOuE203; arc=pass (i=1 spf=pass spfdomain=linux.dev dkim=pass dkdomain=linux.dev dmarc=pass fromdomain=linux.dev); spf=pass (google.com: domain of linux-kernel+bounces-73891-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-73891-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.dev Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [2604:1380:45e3:2400::1]) by mx.google.com with ESMTPS id cu17-20020a05663848d100b0047444df6eecsi111075jab.156.2024.02.20.17.02.12 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 20 Feb 2024 17:02:13 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-73891-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) client-ip=2604:1380:45e3:2400::1; Authentication-Results: mx.google.com; dkim=pass header.i=@linux.dev header.s=key1 header.b=BlOuE203; arc=pass (i=1 spf=pass spfdomain=linux.dev dkim=pass dkdomain=linux.dev dmarc=pass fromdomain=linux.dev); spf=pass (google.com: domain of linux-kernel+bounces-73891-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45e3:2400::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-73891-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linux.dev Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id D1E92280F78 for ; Wed, 21 Feb 2024 01:02:12 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id DC1C53D8E; Wed, 21 Feb 2024 01:02:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="BlOuE203" Received: from out-189.mta0.migadu.com (out-189.mta0.migadu.com [91.218.175.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0D0F117D5 for ; Wed, 21 Feb 2024 01:01:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.189 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708477323; cv=none; b=VBnel3L8nEQfWuOpuGBKcPl6ZKjWXl0U+HZd6eJwd2MjLevTTJIcjKu8A5/TCjPCZ4+8qXp/CGx2uKqOQyG1EAZv7egx9t14UH67T1p/RUDHh7ZJCRBcmRlBstXNui7cO5hama1zLHSddIPhfT5dN/YJrCpiHDfwpuSBBpO8fYg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708477323; c=relaxed/simple; bh=q0d1zg0VgA1XWsqbYGQzwBgECXRcH49a2hn1QrncaLE=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=BY0frpLSTzE/uTqAXp3inNoS+VIhmuklobfwrhsetQLGQnjvHXAjMXoF9ZHjUOdhLj7Dm8OeiC9cQvg1NMqzDGqurpOPJ0sNZXoNlaHXu3YKUI7ZjUMZrkBTX+kFjwWU2sPsK3p3vQKCmNcr458Bf5MsGMjLhOtDVbqiusGAAVY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=BlOuE203; arc=none smtp.client-ip=91.218.175.189 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Date: Tue, 20 Feb 2024 20:01:43 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1708477318; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gVSQ1AUX97J8Bh4kyQx7tym/UpGwt+ikMSltFXfe7fU=; b=BlOuE203eXmrOVV+1v3BlJ1b57CDxMrfn4G0V8MRHEVPNmtOst34uGjS8LqJAuNUT6CUPY ChaOBmlSkHL2e35TYVP5XelwCd9n/UfoM5EGhR3f3oTfdvzmTjE5Bf/NZJ17j9xycGTyLc eLzhlm7iTF1UJZYYyCp946TdV+xZhBg= X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. From: Kent Overstreet To: =?utf-8?B?U3TDqXBoYW5l?= Graber Cc: James Bottomley , linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, lsf-pc@lists.linux-foundation.org, Christian Brauner , Aleksandr Mikhalitsyn Subject: Re: [LSF TOPIC] beyond uidmapping, & towards a better security model Message-ID: References: <141b4c7ecda2a8c064586d064b8d1476d8de3617.camel@HansenPartnership.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: X-Migadu-Flow: FLOW_OUT On Tue, Feb 20, 2024 at 07:56:32PM -0500, Stéphane Graber wrote: > Hey there, > > Sorry, I don't have the time to go through all the details in this > post to provide an adequate response, I'm adding Aleksandr who may be > able to provide more details on what we've been up to (what James > alluded to). > > Our proposal is effectively bumping the in-kernel kuid_t/kgid_t from > uint32 to uint64, which allows for individual user namespaces to get a > full usable uint32 uid/gid range in the kernel. Obviously any kind of > data persistence needs some mapping (VFS idmap) and there are a bunch > of other corner cases as to how this is all exposed to userspace. > > The idea around this stuff started back at Plumbers / Kernel summit > all the way back in 2019 with a bit of refinement on the idea on and > off ever since. > We now have a functional patchset and example userspace code at: > - https://github.com/mihalicyn/isolated-userns > - https://github.com/mihalicyn/linux/commits/isolated_userns > > If you don't mind watching a video, we have a reasonably detailed talk > on the topic as well as demo and useful audience questions and > feedback from FOSDEM here: https://www.youtube.com/watch?v=mOLzSzpVwHU > > After talking about this with folks at a number of LPC / kernel summit > / FOSDEM by this point, our next step is going to be an RFC patchset, > I think at this point we just want the cgroupfs issue sorted out > before sending that out. > > I'll try to set some time to go through your full e-mail later this > week if Alex doesn't get to it first! Looking forward to it!