[PATCH 7/8] loopfs: start attaching correct namespace during loop_add()

From: Christian Brauner
Date: Wed Apr 08 2020 - 11:22:58 EST


Now that kernfs and the block_class optionally support setting user
namespace tags we can start tagging loop devices with the namespace the
loopfs instance was mounted in. This has the consequence that loopfs
devices carry the correct sysfs permissions for all their core files.
All other classes will continue to be correctly owned by the initial
namespaces. Here is sample output:

root@b1:~# mount -t loop loop /mnt
root@b1:~# ln -sf /mnt/loop-control /dev/loop-control
root@b1:~# losetup -f
/dev/loop8
root@b1:~# ln -sf /mnt/loop8 /dev/loop8
root@b1:~# ls -al /sys/class/block/loop8
lrwxrwxrwx 1 root root 0 Apr 7 13:06 /sys/class/block/loop8 -> ../../devices/virtual/block/loop8
root@b1:~# ls -al /sys/class/block/loop8/
total 0
drwxr-xr-x 9 root root 0 Apr 7 13:06 .
drwxr-xr-x 18 nobody nogroup 0 Apr 7 13:07 ..
-r--r--r-- 1 root root 4096 Apr 7 13:06 alignment_offset
lrwxrwxrwx 1 nobody nogroup 0 Apr 7 13:07 bdi -> ../../bdi/7:8
-r--r--r-- 1 root root 4096 Apr 7 13:06 capability
-r--r--r-- 1 root root 4096 Apr 7 13:06 dev
-r--r--r-- 1 root root 4096 Apr 7 13:06 discard_alignment
-r--r--r-- 1 root root 4096 Apr 7 13:06 events
-r--r--r-- 1 root root 4096 Apr 7 13:06 events_async
-rw-r--r-- 1 root root 4096 Apr 7 13:06 events_poll_msecs
-r--r--r-- 1 root root 4096 Apr 7 13:06 ext_range
-r--r--r-- 1 root root 4096 Apr 7 13:06 hidden
drwxr-xr-x 2 nobody nogroup 0 Apr 7 13:07 holders
-r--r--r-- 1 root root 4096 Apr 7 13:06 inflight
drwxr-xr-x 2 nobody nogroup 0 Apr 7 13:07 integrity
drwxr-xr-x 3 nobody nogroup 0 Apr 7 13:07 mq
drwxr-xr-x 2 root root 0 Apr 7 13:06 power
drwxr-xr-x 3 nobody nogroup 0 Apr 7 13:07 queue
-r--r--r-- 1 root root 4096 Apr 7 13:06 range
-r--r--r-- 1 root root 4096 Apr 7 13:06 removable
-r--r--r-- 1 root root 4096 Apr 7 13:06 ro
-r--r--r-- 1 root root 4096 Apr 7 13:06 size
drwxr-xr-x 2 nobody nogroup 0 Apr 7 13:07 slaves
-r--r--r-- 1 root root 4096 Apr 7 13:06 stat
lrwxrwxrwx 1 nobody nogroup 0 Apr 7 13:07 subsystem -> ../../../../class/block
drwxr-xr-x 2 root root 0 Apr 7 13:06 trace
-rw-r--r-- 1 root root 4096 Apr 7 13:06 uevent
root@b1:~#

Cc: Jens Axboe <axboe@xxxxxxxxx>
Signed-off-by: Christian Brauner <christian.brauner@xxxxxxxxxx>
---
drivers/block/loop.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index b1c3436d6e38..7a14fd3e4329 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -2154,6 +2154,10 @@ static int loop_add(struct loop_device **l, int i, struct inode *inode)
disk->private_data = lo;
disk->queue = lo->lo_queue;
sprintf(disk->disk_name, "loop%d", i);
+#ifdef CONFIG_BLK_DEV_LOOPFS
+ if (loopfs_i_sb(inode))
+ disk->user_ns = loopfs_i_sb(inode)->s_user_ns;
+#endif

add_disk(disk);

--
2.26.0