Skip to content
Snippets Groups Projects
user avatar
Eric W. Biederman authored
The v3 file capabilities have a uid field that records the filesystem
uid of the root user of the user namespace the file capabilities are
valid in.

When someone is silly enough to have the same underlying uid as the
root uid of multiple nested containers a v3 filesystem capability can
be ambiguous.

In the spirit of don't do that then, forbid writing a v3 filesystem
capability if it is ambiguous.

Fixes: 8db6c34f ("Introduce v3 namespaced file capabilities")
Reviewed-by: default avatarAndrew G. Morgan <morgan@kernel.org>
Reviewed-by: default avatarSerge Hallyn <serge@hallyn.com>
Signed-off-by: default avatarEric W. Biederman <ebiederm@xmission.com>
95ebabde
History
Name Last commit Last update