From: Al Viro <viro@zeniv•linux.org.uk>
To: Aleksa Sarai <cyphar@cyphar•com>
Cc: linux-ia64@vger•kernel.org, linux-sh@vger•kernel.org,
Peter Zijlstra <peterz@infradead•org>,
Rasmus Villemoes <linux@rasmusvillemoes•dk>,
Alexei Starovoitov <ast@kernel•org>,
linux-kernel@vger•kernel.org, David Howells <dhowells@redhat•com>,
linux-kselftest@vger•kernel.org, sparclinux@vger•kernel.org,
Christian Brauner <christian.brauner@ubuntu•com>,
Shuah Khan <shuah@kernel•org>,
linux-arch@vger•kernel.org, linux-s390@vger•kernel.org,
Tycho Andersen <tycho@tycho•ws>, Aleksa Sarai <asarai@suse•de>,
Jiri Olsa <jolsa@redhat•com>,
Alexander Shishkin <alexander.shishkin@linux•intel.com>,
Ingo Molnar <mingo@redhat•com>,
linux-arm-kernel@lists•infradead.org, linux-mips@vger•kernel.org,
linux-xtensa@linux-xtensa•org, Kees Cook <keescook@chromium•org>,
Arnd Bergmann <arnd@arndb•de>, Jann Horn <jannh@google•com>,
linuxppc-dev@lists•ozlabs.org, linux-m68k@lists•linux-m68k.org,
Andy Lutomirski <luto@kernel•org>,
Shuah Khan <skhan@linuxfoundation•org>,
Namhyung Kim <namhyung@kernel•org>,
David Drysdale <drysdale@google•com>,
Christian Brauner <christian@brauner•io>,
"J. Bruce Fields" <bfields@fieldses•org>,
libc-alpha@sourceware•org, linux-parisc@vger•kernel.org,
linux-api@vger•kernel.org, Chanho Min <chanho.min@lge•com>,
Jeff Layton <jlayton@kernel•org>, Oleg Nesterov <oleg@redhat•com>,
Eric Biederman <ebiederm@xmission•com>,
linux-alpha@vger•kernel.org, linux-fsdevel@vger•kernel.org,
Andrew Morton <akpm@linux-foundation•org>,
Linus Torvalds <torvalds@linux-foundation•org>,
containers@lists•linux-foundation.org
Subject: Re: [PATCH v15 4/9] namei: LOOKUP_BENEATH: O_BENEATH-like scoped resolution
Date: Wed, 13 Nov 2019 01:55:34 +0000 [thread overview]
Message-ID: <20191113015534.GA26530@ZenIV.linux.org.uk> (raw)
In-Reply-To: <20191105090553.6350-5-cyphar@cyphar.com>
On Tue, Nov 05, 2019 at 08:05:48PM +1100, Aleksa Sarai wrote:
Minor nit here - I'd split "move the conditional call of set_root()
into nd_jump_root()" into a separate patch before that one. Makes
for fewer distractions in this one. I'd probably fold "and be
ready for errors other than -ECHILD" into the same preliminary
patch.
> + /* Not currently safe for scoped-lookups. */
> + if (unlikely(nd->flags & LOOKUP_IS_SCOPED))
> + return ERR_PTR(-EXDEV);
Also a candidate for doing in nd_jump_link()...
> @@ -1373,8 +1403,11 @@ static int follow_dotdot_rcu(struct nameidata *nd)
> struct inode *inode = nd->inode;
>
> while (1) {
> - if (path_equal(&nd->path, &nd->root))
> + if (path_equal(&nd->path, &nd->root)) {
> + if (unlikely(nd->flags & LOOKUP_BENEATH))
> + return -EXDEV;
Umm... Are you sure it's not -ECHILD?
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists•infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
WARNING: multiple messages have this Message-ID (diff)
From: Al Viro <viro@zeniv•linux.org.uk>
To: Aleksa Sarai <cyphar@cyphar•com>
Cc: Jeff Layton <jlayton@kernel•org>,
"J. Bruce Fields" <bfields@fieldses•org>,
Arnd Bergmann <arnd@arndb•de>,
David Howells <dhowells@redhat•com>,
Shuah Khan <shuah@kernel•org>,
Shuah Khan <skhan@linuxfoundation•org>,
Ingo Molnar <mingo@redhat•com>,
Peter Zijlstra <peterz@infradead•org>,
Christian Brauner <christian.brauner@ubuntu•com>,
David Drysdale <drysdale@google•com>,
Andy Lutomirski <luto@kernel•org>,
Linus Torvalds <torvalds@linux-foundation•org>,
Eric Biederman <ebiederm@xmission•com>,
Andrew Morton <akpm@linux-foundation•org>,
Alexei Starovoitov <ast@kernel•org>,
Kees Cook <keescook@chromium•org>, Jann Horn <jannh@google•com>,
Tycho Andersen <tycho@tycho•ws>, Chanho Min <chanho.min@lge•com>,
Oleg Nesterov <oleg@redhat•com>,
Rasmus Villemoes <linux@rasmusvillemoes•dk>,
Alexander Shishkin <alexander.shishkin@linux•intel.com>,
Jiri Olsa <jolsa@redhat•com>, Namhyung Kim <namhyung@kernel•org>,
Christian Brauner <christian@brauner•io>,
Aleksa Sarai <asarai@suse•de>,
containers@lists•linux-foundation.org,
linux-alpha@vger•kernel.org, linux-api@vger•kernel.org,
libc-alpha@sourceware•org, linux-arch@vger•kernel.org,
linux-arm-kernel@lists•infradead.org,
linux-fsdevel@vger•kernel.org, linux-ia64@vger•kernel.org,
linux-kernel@vger•kernel.org, linux-kselftest@vger•kernel.org,
linux-m68k@lists•linux-m68k.org, linux-mips@vger•kernel.org,
linux-parisc@vger•kernel.org, linuxppc-dev@lists•ozlabs.org,
linux-s390@vger•kernel.org, linux-sh@vger•kernel.org,
linux-xtensa@linux-xtensa•org, sparclinux@vger•kernel.org
Subject: Re: [PATCH v15 4/9] namei: LOOKUP_BENEATH: O_BENEATH-like scoped resolution
Date: Wed, 13 Nov 2019 01:55:34 +0000 [thread overview]
Message-ID: <20191113015534.GA26530@ZenIV.linux.org.uk> (raw)
Message-ID: <20191113015534.N1Epg3RqYowSgws4j34e_nUbUaV_aqa3yyXMWktKBmI@z> (raw)
In-Reply-To: <20191105090553.6350-5-cyphar@cyphar.com>
On Tue, Nov 05, 2019 at 08:05:48PM +1100, Aleksa Sarai wrote:
Minor nit here - I'd split "move the conditional call of set_root()
into nd_jump_root()" into a separate patch before that one. Makes
for fewer distractions in this one. I'd probably fold "and be
ready for errors other than -ECHILD" into the same preliminary
patch.
> + /* Not currently safe for scoped-lookups. */
> + if (unlikely(nd->flags & LOOKUP_IS_SCOPED))
> + return ERR_PTR(-EXDEV);
Also a candidate for doing in nd_jump_link()...
> @@ -1373,8 +1403,11 @@ static int follow_dotdot_rcu(struct nameidata *nd)
> struct inode *inode = nd->inode;
>
> while (1) {
> - if (path_equal(&nd->path, &nd->root))
> + if (path_equal(&nd->path, &nd->root)) {
> + if (unlikely(nd->flags & LOOKUP_BENEATH))
> + return -EXDEV;
Umm... Are you sure it's not -ECHILD?
next prev parent reply other threads:[~2019-11-13 1:56 UTC|newest]
Thread overview: 49+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-11-05 9:05 [PATCH v15 0/9] open: introduce openat2(2) syscall Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 1/9] namei: LOOKUP_NO_SYMLINKS: block symlink resolution Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 2/9] namei: LOOKUP_NO_MAGICLINKS: block magic-link resolution Aleksa Sarai
2019-11-13 1:24 ` Al Viro
2019-11-13 1:24 ` Al Viro
2019-11-05 9:05 ` [PATCH v15 3/9] namei: LOOKUP_NO_XDEV: block mountpoint crossing Aleksa Sarai
2019-11-13 1:36 ` Al Viro
2019-11-13 1:36 ` Al Viro
2019-11-14 4:49 ` Aleksa Sarai
2019-11-14 4:49 ` Aleksa Sarai
2019-11-14 5:43 ` Al Viro
2019-11-14 5:43 ` Al Viro
2019-11-14 13:33 ` Aleksa Sarai
2019-11-14 13:33 ` Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 4/9] namei: LOOKUP_BENEATH: O_BENEATH-like scoped resolution Aleksa Sarai
2019-11-13 1:55 ` Al Viro [this message]
2019-11-13 1:55 ` Al Viro
2019-11-13 7:47 ` Aleksa Sarai
2019-11-13 7:47 ` Aleksa Sarai
2019-11-14 4:57 ` Aleksa Sarai
2019-11-14 4:57 ` Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 5/9] namei: LOOKUP_IN_ROOT: chroot-like " Aleksa Sarai
2019-11-13 2:03 ` Al Viro
2019-11-13 2:03 ` Al Viro
2019-11-13 2:44 ` Aleksa Sarai
2019-11-13 2:44 ` Aleksa Sarai
2019-11-13 2:59 ` Al Viro
2019-11-13 2:59 ` Al Viro
2019-11-13 3:55 ` Aleksa Sarai
2019-11-13 3:55 ` Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 6/9] namei: LOOKUP_{IN_ROOT, BENEATH}: permit limited ".." resolution Aleksa Sarai
2019-11-13 2:09 ` [PATCH v15 6/9] namei: LOOKUP_{IN_ROOT,BENEATH}: " Al Viro
2019-11-13 2:09 ` Al Viro
2019-11-13 7:52 ` Aleksa Sarai
2019-11-13 7:52 ` Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 7/9] open: introduce openat2(2) syscall Aleksa Sarai
2019-11-13 2:29 ` Al Viro
2019-11-13 2:29 ` Al Viro
2019-11-13 2:35 ` Aleksa Sarai
2019-11-13 2:35 ` Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 8/9] selftests: add openat2(2) selftests Aleksa Sarai
2019-11-05 9:05 ` [PATCH v15 9/9] Documentation: path-lookup: mention LOOKUP_MAGICLINK_JUMPED Aleksa Sarai
2019-11-11 13:24 ` [PATCH v15 0/9] open: introduce openat2(2) syscall Aleksa Sarai
2019-11-12 23:01 ` Kees Cook
2019-11-12 23:01 ` Kees Cook
2019-11-12 23:06 ` Christian Brauner
2019-11-12 23:06 ` Christian Brauner
2019-11-13 0:46 ` Aleksa Sarai
2019-11-13 0:46 ` Aleksa Sarai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20191113015534.GA26530@ZenIV.linux.org.uk \
--to=viro@zeniv$(echo .)linux.org.uk \
--cc=akpm@linux-foundation$(echo .)org \
--cc=alexander.shishkin@linux$(echo .)intel.com \
--cc=arnd@arndb$(echo .)de \
--cc=asarai@suse$(echo .)de \
--cc=ast@kernel$(echo .)org \
--cc=bfields@fieldses$(echo .)org \
--cc=chanho.min@lge$(echo .)com \
--cc=christian.brauner@ubuntu$(echo .)com \
--cc=christian@brauner$(echo .)io \
--cc=containers@lists$(echo .)linux-foundation.org \
--cc=cyphar@cyphar$(echo .)com \
--cc=dhowells@redhat$(echo .)com \
--cc=drysdale@google$(echo .)com \
--cc=ebiederm@xmission$(echo .)com \
--cc=jannh@google$(echo .)com \
--cc=jlayton@kernel$(echo .)org \
--cc=jolsa@redhat$(echo .)com \
--cc=keescook@chromium$(echo .)org \
--cc=libc-alpha@sourceware$(echo .)org \
--cc=linux-alpha@vger$(echo .)kernel.org \
--cc=linux-api@vger$(echo .)kernel.org \
--cc=linux-arch@vger$(echo .)kernel.org \
--cc=linux-arm-kernel@lists$(echo .)infradead.org \
--cc=linux-fsdevel@vger$(echo .)kernel.org \
--cc=linux-ia64@vger$(echo .)kernel.org \
--cc=linux-kernel@vger$(echo .)kernel.org \
--cc=linux-kselftest@vger$(echo .)kernel.org \
--cc=linux-m68k@lists$(echo .)linux-m68k.org \
--cc=linux-mips@vger$(echo .)kernel.org \
--cc=linux-parisc@vger$(echo .)kernel.org \
--cc=linux-s390@vger$(echo .)kernel.org \
--cc=linux-sh@vger$(echo .)kernel.org \
--cc=linux-xtensa@linux-xtensa$(echo .)org \
--cc=linux@rasmusvillemoes$(echo .)dk \
--cc=linuxppc-dev@lists$(echo .)ozlabs.org \
--cc=luto@kernel$(echo .)org \
--cc=mingo@redhat$(echo .)com \
--cc=namhyung@kernel$(echo .)org \
--cc=oleg@redhat$(echo .)com \
--cc=peterz@infradead$(echo .)org \
--cc=shuah@kernel$(echo .)org \
--cc=skhan@linuxfoundation$(echo .)org \
--cc=sparclinux@vger$(echo .)kernel.org \
--cc=torvalds@linux-foundation$(echo .)org \
--cc=tycho@tycho$(echo .)ws \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox