Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932295Ab1BXDPH (ORCPT ); Wed, 23 Feb 2011 22:15:07 -0500 Received: from 184-106-158-135.static.cloud-ips.com ([184.106.158.135]:56961 "EHLO mail" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S932071Ab1BXDPF (ORCPT ); Wed, 23 Feb 2011 22:15:05 -0500 Date: Thu, 24 Feb 2011 03:15:18 +0000 From: "Serge E. Hallyn" To: Andrew Morton Cc: "Serge E. Hallyn" , "Eric W. Biederman" , LSM , James Morris , Kees Cook , containers@lists.linux-foundation.org, kernel list , Alexey Dobriyan , Michael Kerrisk , xemul@parallels.com, dhowells@redhat.com Subject: Re: [PATCH] userns: ptrace: incorporate feedback from Eric Message-ID: <20110224031518.GA4963@mail.hallyn.com> References: <20110217150224.GA26334@mail.hallyn.com> <20110217150333.GE26395@mail.hallyn.com> <20110218043601.GB9584@mail.hallyn.com> <20110224004901.GB11822@mail.hallyn.com> <20110223165651.cf248f3b.akpm@linux-foundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20110223165651.cf248f3b.akpm@linux-foundation.org> User-Agent: Mutt/1.5.20 (2009-06-14) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 856 Lines: 23 Quoting Andrew Morton (akpm@linux-foundation.org): > On Thu, 24 Feb 2011 00:49:01 +0000 > "Serge E. Hallyn" wrote: > > > same_or_ancestore_user_ns() was not an appropriate check to > > constrain cap_issubset. Rather, cap_issubset() only is > > meaningful when both capsets are in the same user_ns. > > I queued this as a fix against > userns-allow-ptrace-from-non-init-user-namespaces.patch, but I get the > feeling that it would be better to just drop everything and start > again? Sure, I'll rebase and resend. I wonder if I should trim the Cc list for the next round. thanks, -serge -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/