coda: Restrict coda messages to the initial user namespace
Remove the slight chance that uids and gids in coda messages will be interpreted in the wrong user namespace. - Only allow processes in the initial user namespace to open the coda character device to communicate with coda filesystems. - Explicitly convert the uids in the coda header into the initial user namespace. - In coda_vattr_to_attr make kuids and kgids from the initial user namespace uids and gids in struct coda_vattr that just came from userspace. - In coda_iattr_to_vattr convert kuids and kgids into uids and gids in the intial user namespace and store them in struct coda_vattr for sending to coda userspace programs. Nothing needs to be changed with mounts as coda does not support being mounted in anything other than the initial user namespace. Cc: Jan Harkes <jaharkes@cs.cmu.edu> Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
This commit is contained in:
@@ -52,7 +52,7 @@ static void *alloc_upcall(int opcode, int size)
|
||||
inp->ih.opcode = opcode;
|
||||
inp->ih.pid = task_pid_nr_ns(current, &init_pid_ns);
|
||||
inp->ih.pgid = task_pgrp_nr_ns(current, &init_pid_ns);
|
||||
inp->ih.uid = current_fsuid();
|
||||
inp->ih.uid = from_kuid(&init_user_ns, current_fsuid());
|
||||
|
||||
return (void*)inp;
|
||||
}
|
||||
@@ -157,7 +157,7 @@ int venus_lookup(struct super_block *sb, struct CodaFid *fid,
|
||||
}
|
||||
|
||||
int venus_close(struct super_block *sb, struct CodaFid *fid, int flags,
|
||||
vuid_t uid)
|
||||
kuid_t uid)
|
||||
{
|
||||
union inputArgs *inp;
|
||||
union outputArgs *outp;
|
||||
@@ -166,7 +166,7 @@ int venus_close(struct super_block *sb, struct CodaFid *fid, int flags,
|
||||
insize = SIZE(release);
|
||||
UPARG(CODA_CLOSE);
|
||||
|
||||
inp->ih.uid = uid;
|
||||
inp->ih.uid = from_kuid(&init_user_ns, uid);
|
||||
inp->coda_close.VFid = *fid;
|
||||
inp->coda_close.flags = flags;
|
||||
|
||||
|
Reference in New Issue
Block a user