Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-28 Thread Serge E. Hallyn
Quoting Amir Goldstein (amir7...@gmail.com): > On Wed, Jun 28, 2017 at 8:41 AM, Serge E. Hallyn wrote: > > Hi Amir, > > > > I was liking the prefix at first, but I'm actually not sure it's worth > > it. THe main advantage would be so that checking for namespace or other > > tags could be done alw

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-28 Thread Stefan Berger
On 06/28/2017 03:18 AM, Amir Goldstein wrote: On Wed, Jun 28, 2017 at 8:41 AM, Serge E. Hallyn wrote: On Fri, Jun 23, 2017 at 10:01:46AM +0300, Amir Goldstein wrote: On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger wrote: This series of patches primary goal is to enable file capabilities in us

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-28 Thread Amir Goldstein
On Wed, Jun 28, 2017 at 8:41 AM, Serge E. Hallyn wrote: > On Fri, Jun 23, 2017 at 10:01:46AM +0300, Amir Goldstein wrote: >> On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger >> wrote: >> > This series of patches primary goal is to enable file capabilities >> > in user namespaces without affecting t

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-27 Thread Serge E. Hallyn
On Fri, Jun 23, 2017 at 10:01:46AM +0300, Amir Goldstein wrote: > On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger > wrote: > > This series of patches primary goal is to enable file capabilities > > in user namespaces without affecting the file capabilities that are > > effective on the host. This i

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Casey Schaufler
On 6/23/2017 4:09 PM, Stefan Berger wrote: > On 06/23/2017 02:35 PM, Serge E. Hallyn wrote: >> Quoting Stefan Berger (stef...@linux.vnet.ibm.com): >>> On 06/23/2017 12:16 PM, Casey Schaufler wrote: On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: > Quoting Amir Goldstein (amir7...@gmail.com):

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Stefan Berger
On 06/23/2017 02:35 PM, Serge E. Hallyn wrote: Quoting Stefan Berger (stef...@linux.vnet.ibm.com): On 06/23/2017 12:16 PM, Casey Schaufler wrote: On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: Quoting Amir Goldstein (amir7...@gmail.com): On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger wrote: T

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Vivek Goyal (vgo...@redhat.com): > On Fri, Jun 23, 2017 at 03:17:23PM -0500, Serge E. Hallyn wrote: > > Quoting Vivek Goyal (vgo...@redhat.com): > > > On Thu, Jun 22, 2017 at 02:59:46PM -0400, Stefan Berger wrote: > > > > This series of patches primary goal is to enable file capabilities >

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Vivek Goyal
On Fri, Jun 23, 2017 at 03:17:23PM -0500, Serge E. Hallyn wrote: > Quoting Vivek Goyal (vgo...@redhat.com): > > On Thu, Jun 22, 2017 at 02:59:46PM -0400, Stefan Berger wrote: > > > This series of patches primary goal is to enable file capabilities > > > in user namespaces without affecting the file

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Casey Schaufler
On 6/23/2017 11:35 AM, Serge E. Hallyn wrote: > Quoting Stefan Berger (stef...@linux.vnet.ibm.com): >> On 06/23/2017 12:16 PM, Casey Schaufler wrote: >>> On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: Quoting Amir Goldstein (amir7...@gmail.com): > On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berg

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Vivek Goyal (vgo...@redhat.com): > On Thu, Jun 22, 2017 at 02:59:46PM -0400, Stefan Berger wrote: > > This series of patches primary goal is to enable file capabilities > > in user namespaces without affecting the file capabilities that are > > effective on the host. This is to prevent that

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Vivek Goyal
On Thu, Jun 22, 2017 at 02:59:46PM -0400, Stefan Berger wrote: > This series of patches primary goal is to enable file capabilities > in user namespaces without affecting the file capabilities that are > effective on the host. This is to prevent that any unprivileged user > on the host maps his own

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Eric W. Biederman (ebied...@xmission.com): > Even with one xattr of any type there is something appealing about > putting the logic that limits that xattr to a namespace in the name. As Exactly. That's the idea - from Stefan - that I thought was a worthwhile improvement over my own previ

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Stefan Berger (stef...@linux.vnet.ibm.com): > On 06/23/2017 12:16 PM, Casey Schaufler wrote: > >On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: > >>Quoting Amir Goldstein (amir7...@gmail.com): > >>>On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger > >>> wrote: > This series of patches primary

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Stefan Berger (stef...@linux.vnet.ibm.com): > On 06/23/2017 01:07 PM, James Bottomley wrote: > >On Fri, 2017-06-23 at 11:30 -0500, Serge E. Hallyn wrote: > >>Quoting Casey Schaufler (ca...@schaufler-ca.com): > >>>Or maybe just security.ns.capability, taking James' comment into > >>>account.

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Eric W. Biederman (ebied...@xmission.com): > "Serge E. Hallyn" writes: > > > Quoting Casey Schaufler (ca...@schaufler-ca.com): > >> On 6/23/2017 9:30 AM, Serge E. Hallyn wrote: > >> > Quoting Casey Schaufler (ca...@schaufler-ca.com): > >> >> Or maybe just security.ns.capability, taking Ja

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Stefan Berger
On 06/23/2017 12:16 PM, Casey Schaufler wrote: On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: Quoting Amir Goldstein (amir7...@gmail.com): On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger wrote: This series of patches primary goal is to enable file capabilities in user namespaces without affectin

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Eric W. Biederman
"Serge E. Hallyn" writes: > Quoting Casey Schaufler (ca...@schaufler-ca.com): >> On 6/23/2017 9:30 AM, Serge E. Hallyn wrote: >> > Quoting Casey Schaufler (ca...@schaufler-ca.com): >> >> Or maybe just security.ns.capability, taking James' comment into account. >> > That last one may be suitable a

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Eric W. Biederman
James Bottomley writes: > On Thu, 2017-06-22 at 18:36 -0500, Serge E. Hallyn wrote: >> Quoting James Bottomley (james.bottom...@hansenpartnership.com): >> > On Thu, 2017-06-22 at 14:59 -0400, Stefan Berger wrote: >> > > This series of patches primary goal is to enable file >> > > capabilities in

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Stefan Berger
On 06/23/2017 01:07 PM, James Bottomley wrote: On Fri, 2017-06-23 at 11:30 -0500, Serge E. Hallyn wrote: Quoting Casey Schaufler (ca...@schaufler-ca.com): Or maybe just security.ns.capability, taking James' comment into account. That last one may be suitable as an option, useful for his partic

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting James Bottomley (james.bottom...@hansenpartnership.com): > On Fri, 2017-06-23 at 11:30 -0500, Serge E. Hallyn wrote: > > Quoting Casey Schaufler (ca...@schaufler-ca.com): > > > Or maybe just security.ns.capability, taking James' comment into > > > account. > > > > That last one may be suit

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread James Bottomley
On Fri, 2017-06-23 at 11:30 -0500, Serge E. Hallyn wrote: > Quoting Casey Schaufler (ca...@schaufler-ca.com): > > Or maybe just security.ns.capability, taking James' comment into > > account. > > That last one may be suitable as an option, useful for his particular > (somewhat barbaric :) use case

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Casey Schaufler (ca...@schaufler-ca.com): > On 6/23/2017 9:30 AM, Serge E. Hallyn wrote: > > Quoting Casey Schaufler (ca...@schaufler-ca.com): > >> Or maybe just security.ns.capability, taking James' comment into account. > > That last one may be suitable as an option, useful for his partic

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Casey Schaufler
On 6/23/2017 9:30 AM, Serge E. Hallyn wrote: > Quoting Casey Schaufler (ca...@schaufler-ca.com): >> On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: >>> Quoting Amir Goldstein (amir7...@gmail.com): On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger wrote: > This series of patches primary goa

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Casey Schaufler (ca...@schaufler-ca.com): > On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: > > Quoting Amir Goldstein (amir7...@gmail.com): > >> On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger > >> wrote: > >>> This series of patches primary goal is to enable file capabilities > >>> in user n

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Casey Schaufler
On 6/23/2017 9:00 AM, Serge E. Hallyn wrote: > Quoting Amir Goldstein (amir7...@gmail.com): >> On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger >> wrote: >>> This series of patches primary goal is to enable file capabilities >>> in user namespaces without affecting the file capabilities that are >>>

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Serge E. Hallyn
Quoting Amir Goldstein (amir7...@gmail.com): > On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger > wrote: > > This series of patches primary goal is to enable file capabilities > > in user namespaces without affecting the file capabilities that are > > effective on the host. This is to prevent that a

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-23 Thread Amir Goldstein
On Thu, Jun 22, 2017 at 9:59 PM, Stefan Berger wrote: > This series of patches primary goal is to enable file capabilities > in user namespaces without affecting the file capabilities that are > effective on the host. This is to prevent that any unprivileged user > on the host maps his own uid to

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Serge E. Hallyn
Quoting James Bottomley (james.bottom...@hansenpartnership.com): > On Thu, 2017-06-22 at 18:36 -0500, Serge E. Hallyn wrote: > > Yes, the use case is: to allow root in the container to set the > > privilege itself, without endangering any resources not owned by > > that root. > > OK, so you envisa

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread James Bottomley
On Thu, 2017-06-22 at 18:36 -0500, Serge E. Hallyn wrote: > Quoting James Bottomley (james.bottom...@hansenpartnership.com): > > On Thu, 2017-06-22 at 14:59 -0400, Stefan Berger wrote: > > > This series of patches primary goal is to enable file > > > capabilities in user namespaces without affecti

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Serge E. Hallyn
Quoting James Bottomley (james.bottom...@hansenpartnership.com): > On Thu, 2017-06-22 at 14:59 -0400, Stefan Berger wrote: > > This series of patches primary goal is to enable file capabilities > > in user namespaces without affecting the file capabilities that are > > effective on the host. This i

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Serge E. Hallyn
Quoting James Bottomley (james.bottom...@hansenpartnership.com): > On Thu, 2017-06-22 at 14:59 -0400, Stefan Berger wrote: > > This series of patches primary goal is to enable file capabilities > > in user namespaces without affecting the file capabilities that are > > effective on the host. This i

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread James Bottomley
On Thu, 2017-06-22 at 14:59 -0400, Stefan Berger wrote: > This series of patches primary goal is to enable file capabilities > in user namespaces without affecting the file capabilities that are > effective on the host. This is to prevent that any unprivileged user > on the host maps his own uid to

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Serge E. Hallyn
Quoting Casey Schaufler (ca...@schaufler-ca.com): > On 6/22/2017 2:09 PM, Serge E. Hallyn wrote: > > Quoting Casey Schaufler (ca...@schaufler-ca.com): > >> On 6/22/2017 1:12 PM, Stefan Berger wrote: > >>> On 06/22/2017 03:59 PM, Casey Schaufler wrote: > On 6/22/2017 11:59 AM, Stefan Berger wro

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Casey Schaufler
On 6/22/2017 2:09 PM, Serge E. Hallyn wrote: > Quoting Casey Schaufler (ca...@schaufler-ca.com): >> On 6/22/2017 1:12 PM, Stefan Berger wrote: >>> On 06/22/2017 03:59 PM, Casey Schaufler wrote: On 6/22/2017 11:59 AM, Stefan Berger wrote: > This series of patches primary goal is to enable f

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Serge E. Hallyn
Quoting Casey Schaufler (ca...@schaufler-ca.com): > On 6/22/2017 1:12 PM, Stefan Berger wrote: > > On 06/22/2017 03:59 PM, Casey Schaufler wrote: > >> On 6/22/2017 11:59 AM, Stefan Berger wrote: > >>> This series of patches primary goal is to enable file capabilities > >>> in user namespaces withou

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Stefan Berger
On 06/22/2017 04:33 PM, Casey Schaufler wrote: On 6/22/2017 1:12 PM, Stefan Berger wrote: On 06/22/2017 03:59 PM, Casey Schaufler wrote: On 6/22/2017 11:59 AM, Stefan Berger wrote: This series of patches primary goal is to enable file capabilities in user namespaces without affecting the file

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Casey Schaufler
On 6/22/2017 1:12 PM, Stefan Berger wrote: > On 06/22/2017 03:59 PM, Casey Schaufler wrote: >> On 6/22/2017 11:59 AM, Stefan Berger wrote: >>> This series of patches primary goal is to enable file capabilities >>> in user namespaces without affecting the file capabilities that are >>> effective on

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Stefan Berger
On 06/22/2017 03:59 PM, Casey Schaufler wrote: On 6/22/2017 11:59 AM, Stefan Berger wrote: This series of patches primary goal is to enable file capabilities in user namespaces without affecting the file capabilities that are effective on the host. This is to prevent that any unprivileged user o

Re: [PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Casey Schaufler
On 6/22/2017 11:59 AM, Stefan Berger wrote: > This series of patches primary goal is to enable file capabilities > in user namespaces without affecting the file capabilities that are > effective on the host. This is to prevent that any unprivileged user > on the host maps his own uid to root in a p

[PATCH 0/3] Enable namespaced file capabilities

2017-06-22 Thread Stefan Berger
This series of patches primary goal is to enable file capabilities in user namespaces without affecting the file capabilities that are effective on the host. This is to prevent that any unprivileged user on the host maps his own uid to root in a private namespace, writes the xattr, and executes the