summaryrefslogtreecommitdiff
path: root/fs
diff options
context:
space:
mode:
authorAndy Lutomirski <luto@amacapital.net>2013-04-14 18:44:04 (GMT)
committerAndy Lutomirski <luto@amacapital.net>2013-04-15 01:11:32 (GMT)
commit41c21e351e79004dbb4efa4bc14a53a7e0af38c5 (patch)
tree09f41257304634a6f2dcf48fd99504924a5344f1 /fs
parente3211c120a85b792978bcb4be7b2886df18d27f0 (diff)
downloadlinux-fsl-qoriq-41c21e351e79004dbb4efa4bc14a53a7e0af38c5.tar.xz
userns: Changing any namespace id mappings should require privileges
Changing uid/gid/projid mappings doesn't change your id within the namespace; it reconfigures the namespace. Unprivileged programs should *not* be able to write these files. (We're also checking the privileges on the wrong task.) Given the write-once nature of these files and the other security checks, this is likely impossible to usefully exploit. Signed-off-by: Andy Lutomirski <luto@amacapital.net>
Diffstat (limited to 'fs')
0 files changed, 0 insertions, 0 deletions