From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public•gmane.org (Eric W. Biederman)
To: "Rémi Denis-Courmont" <remi-AzDNUFsAnHasTnJN9+BGXg@public•gmane.org>
Cc: netdev-u79uwXL29TY76Z2rM5mHXA@public•gmane.org,
containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public•gmane.org,
linux-kernel-u79uwXL29TY76Z2rM5mHXA@public•gmane.org
Subject: Re: [PATCH 06/21] userns: Print out socket uids in a user namespace aware fashion.
Date: Tue, 14 Aug 2012 21:47:09 -0700 [thread overview]
Message-ID: <87has4hicy.fsf@xmission.com> (raw)
In-Reply-To: <201208132326.35045.remi-AzDNUFsAnHasTnJN9+BGXg@public.gmane.org> ("Rémi Denis-Courmont"'s message of "Mon, 13 Aug 2012 23:26:34 +0300")
"Rémi Denis-Courmont" <remi@remlab•net> writes:
> Le lundi 13 août 2012 23:18:20, vous avez écrit :
>> From: "Eric W. Biederman" <ebiederm@xmission•com>
>>
>> Cc: David Miller <davem@davemloft•net>
>> Cc: Alexey Kuznetsov <kuznet@ms2•inr.ac.ru>
>> Cc: James Morris <jmorris@namei•org>
>> Cc: Hideaki YOSHIFUJI <yoshfuji@linux-ipv6•org>
>> Cc: Patrick McHardy <kaber@trash•net>
>> Cc: Arnaldo Carvalho de Melo <acme@ghostprotocols•net>
>> Cc: Vlad Yasevich <vyasevich@gmail•com>
>> Cc: Sridhar Samudrala <sri@us•ibm.com>
>> Acked-by: Serge Hallyn <serge.hallyn@canonical•com>
>> Signed-off-by: Eric W. Biederman <ebiederm@xmission•com>
>
> FWIW, ...
Well I will take every bit of review I can get. It can be terribly
embarrassing to discover you messed up uid/gid handling and no one
noticed the security hole for 3 kernel releases...
> Acked-By: Rémi Denis-Courmont <remi@remlab•net>
_______________________________________________
Containers mailing list
Containers@lists•linux-foundation.org
https://lists.linuxfoundation.org/mailman/listinfo/containers
next prev parent reply other threads:[~2012-08-15 4:47 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-08-13 20:07 [REVIEW][PATCH 0/21] User namespace changes to the networking stack Eric W. Biederman
[not found] ` <87ehnav9n5.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:18 ` [PATCH 01/21] userns: Convert net/core/scm.c to use kuids and kgids Eric W. Biederman
[not found] ` <1344889115-21610-1-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:18 ` [PATCH 02/21] userns: Convert __dev_set_promiscuity to use kuids in audit logs Eric W. Biederman
2012-08-13 20:18 ` [PATCH 03/21] userns: Convert sock_i_uid to return a kuid_t Eric W. Biederman
2012-08-13 20:18 ` [PATCH 04/21] userns: Allow USER_NS and NET simultaneously in Kconfig Eric W. Biederman
2012-08-13 20:18 ` [PATCH 05/21] userns: Make seq_file's user namespace accessible Eric W. Biederman
2012-08-13 20:18 ` [PATCH 06/21] userns: Print out socket uids in a user namespace aware fashion Eric W. Biederman
[not found] ` <1344889115-21610-6-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:26 ` Rémi Denis-Courmont
[not found] ` <201208132326.35045.remi-AzDNUFsAnHasTnJN9+BGXg@public.gmane.org>
2012-08-15 4:47 ` Eric W. Biederman [this message]
2012-08-15 3:22 ` Vlad Yasevich
2012-08-13 20:18 ` [PATCH 07/21] userns: Use kgids for sysctl_ping_group_range Eric W. Biederman
[not found] ` <1344889115-21610-7-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-20 18:09 ` Vasiliy Kulikov
2012-08-13 20:18 ` [PATCH 08/21] net ip6 flowlabel: Make owner a union of struct pid * and kuid_t Eric W. Biederman
2012-08-13 20:18 ` [PATCH 09/21] pidns: Export free_pid_ns Eric W. Biederman
2012-08-13 20:18 ` [PATCH 11/21] netlink: Make the sending netlink socket availabe in NETLINK_CB Eric W. Biederman
2012-08-13 20:18 ` [PATCH 12/21] userns: Implement sk_user_ns Eric W. Biederman
2012-08-13 20:18 ` [PATCH 13/21] userns: Teach inet_diag to work with user namespaces Eric W. Biederman
[not found] ` <1344889115-21610-13-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-14 8:35 ` Pavel Emelyanov
2012-08-13 20:18 ` [PATCH 14/21] userns: nfnetlink_log: Report socket uids in the log sockets user namespace Eric W. Biederman
2012-08-13 20:18 ` [PATCH 15/21] net sched: Pass the skb into change so it can access NETLINK_CB Eric W. Biederman
[not found] ` <1344889115-21610-15-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-15 8:11 ` Jamal Hadi Salim
2012-08-13 20:18 ` [PATCH 16/21] userns: Convert cls_flow to work with user namespaces enabled Eric W. Biederman
2012-08-13 20:18 ` [PATCH 17/21] userns: Convert xt_LOG to print socket kuids and kgids as uids and gids Eric W. Biederman
2012-08-13 20:18 ` [PATCH 18/21] userns xt_recent: Specify the owner/group of ip_list_perms in the initial user namespace Eric W. Biederman
2012-08-13 20:18 ` [PATCH 19/21] userns: xt_owner: Add basic user namespace support Eric W. Biederman
2012-08-13 20:18 ` [PATCH 20/21] userns: Make the airo wireless driver use kuids for proc uids and gids Eric W. Biederman
2012-08-13 20:18 ` [PATCH 21/21] userns: Convert tun/tap to use kuid and kgid where appropriate Eric W. Biederman
2012-08-13 20:18 ` [PATCH 10/21] userns: Convert net/ax25 to use kuid_t " Eric W. Biederman
2012-08-15 0:12 ` [REVIEW][PATCH 0/21] User namespace changes to the networking stack David Miller
2012-08-15 0:47 ` Eric W. Biederman
[not found] ` <20120814.171203.1784557890475348401.davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
2012-08-15 6:37 ` Eric W. Biederman
[not found] ` <87boicfyo9.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-25 1:42 ` David Miller
[not found] ` <20120824.214237.2157641321364380276.davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
2012-08-25 3:46 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87has4hicy.fsf@xmission.com \
--to=ebiederm-as9lmozglivwk0htik3j/w@public$(echo .)gmane.org \
--cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public$(echo .)gmane.org \
--cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public$(echo .)gmane.org \
--cc=netdev-u79uwXL29TY76Z2rM5mHXA@public$(echo .)gmane.org \
--cc=remi-AzDNUFsAnHasTnJN9+BGXg@public$(echo .)gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox