Re: [Devel] Re: [patch 05/10] add "permit user mounts in new namespace" clone flag

From: Eric W. Biederman
Date: Mon Apr 16 2007 - 11:46:13 EST


Miklos Szeredi <miklos@xxxxxxxxxx> writes:

> That depends. Current patches check the "unprivileged submounts
> allowed under this mount" flag only on the requested mount and not on
> the propagated mounts. Do you see a problem with this?

I think privileges of this sort should propagate. If I read what you
just said correctly if I have a private mount namespace I won't be able
to mount anything unless when it was setup the unprivileged submount
command was explicitly set.

Eric
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/