Re: [RFC PATCH 0/5] allow unprivileged overlay mounts
From: Miklos Szeredi
Date: Mon Nov 25 2019 - 10:14:15 EST
On Fri, Oct 25, 2019 at 3:43 PM Eric W. Biederman <ebiederm@xxxxxxxxxxxx> wrote:
>
> Miklos Szeredi <mszeredi@xxxxxxxxxx> writes:
>
> > Hi Eric,
> >
> > Can you please have a look at this patchset?
> >
> > The most interesting one is the last oneliner adding FS_USERNS_MOUNT;
> > whether I'm correct in stating that this isn't going to introduce any
> > holes, or not...
>
> I will take some time and dig through this.
>
> From a robustness standpoint I worry about the stackable filesystem
> side. As that is uniquely an attack vector with overlayfs.
>
> There is definitely demand for this.
Hi Eric,
Have you had time to look into this yet?
Thanks,
Miklos