Re: [PATCH] shmem: restrict noswap option to initial user namespace

From: Luis Chamberlain
Date: Thu Apr 20 2023 - 15:18:42 EST


On Thu, Apr 20, 2023 at 10:57:43AM +0200, Christian Brauner wrote:
> Prevent tmpfs instances mounted in an unprivileged namespaces from
> evading accounting of locked memory by using the "noswap" mount option.
>
> Cc: Luis Chamberlain <mcgrof@xxxxxxxxxx>
> Reported-by: Hugh Dickins <hughd@xxxxxxxxxx>
> Link: https://lore.kernel.org/lkml/79eae9fe-7818-a65c-89c6-138b55d609a@xxxxxxxxxx
> Signed-off-by: Christian Brauner <brauner@xxxxxxxxxx>

Reviewed-by: Luis Chamberlain <mcgrof@xxxxxxxxxx>

Luis