[Devel] [patch -mm 12/17] user namespace: hook permission
clg at fr.ibm.com
clg at fr.ibm.com
Tue Dec 5 02:28:04 PST 2006
From: Serge Hallyn <serue at us.ibm.com>
Hook permission to check vfsmnt->user_ns against current.
Signed-off-by: Serge E. Hallyn <serue at us.ibm.com>
---
fs/namei.c | 4 ++++
1 file changed, 4 insertions(+)
Index: 2.6.19-rc6-mm2/fs/namei.c
===================================================================
--- 2.6.19-rc6-mm2.orig/fs/namei.c
+++ 2.6.19-rc6-mm2/fs/namei.c
@@ -246,6 +246,8 @@ int permission(struct inode *inode, int
return -EACCES;
}
+ if (nd && !task_mnt_same_uid(current, nd->mnt))
+ return -EACCES;
/*
* MAY_EXEC on regular files requires special handling: We override
@@ -433,6 +435,8 @@ static int exec_permission_lite(struct i
{
umode_t mode = inode->i_mode;
+ if (!task_mnt_same_uid(current, nd->mnt))
+ return -EACCES;
if (inode->i_op && inode->i_op->permission)
return -EAGAIN;
--
_______________________________________________
Containers mailing list
Containers at lists.osdl.org
https://lists.osdl.org/mailman/listinfo/containers
More information about the Devel
mailing list