[Devel] Re: [patch 0/8] unprivileged mount syscall
Miklos Szeredi
miklos at szeredi.hu
Wed Apr 11 03:48:34 PDT 2007
> > >>
> > >> - users can use bind mounts without having to pre-configure them in
> > >> /etc/fstab
> > >>
> >
> > This is by far the biggest concern I see. I think the security
> > implication of allowing anyone to do bind mounts are poorly understood.
>
> And especially so since there is no way for a filesystem module to veto
> such requests.
The filesystem can't veto initial mounts based on destination either.
I don't think it's up to the filesystem to police bind/move mounts in
any way.
Miklos
_______________________________________________
Containers mailing list
Containers at lists.linux-foundation.org
https://lists.linux-foundation.org/mailman/listinfo/containers
More information about the Devel
mailing list