[Top] [All Lists]

Re: [PATCH review 05/16] xfs: Update xfs_ioctl_setattr to handle projids

To: Dave Chinner <david@xxxxxxxxxxxxx>
Subject: Re: [PATCH review 05/16] xfs: Update xfs_ioctl_setattr to handle projids in any user namespace
From: Gao feng <gaofeng@xxxxxxxxxxxxxx>
Date: Tue, 30 Jul 2013 12:04:38 +0800
Cc: dwight.engen@xxxxxxxxxx, "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>, linux-fsdevel@xxxxxxxxxxxxxxx, Linux Containers <containers@xxxxxxxxxxxxxxxxxxxxxxxxxx>, linux-kernel@xxxxxxxxxxxxxxx, "Serge E. Hallyn" <serge@xxxxxxxxxx>, Ben Myers <bpm@xxxxxxx>, Alex Elder <elder@xxxxxxxxxx>, xfs@xxxxxxxxxxx
Delivered-to: xfs@xxxxxxxxxxx
In-reply-to: <20130730035748.GJ21982@dastard>
References: <87txpaph4n.fsf@xxxxxxxxxxxx> <1361149870-27732-1-git-send-email-ebiederm@xxxxxxxxxxxx> <1361149870-27732-5-git-send-email-ebiederm@xxxxxxxxxxxx> <20130219015550.GJ26694@dastard> <51F616F2.5040906@xxxxxxxxxxxxxx> <20130729075109.GF13468@dastard> <51F72FE6.4080202@xxxxxxxxxxxxxx> <20130730035748.GJ21982@dastard>
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130625 Thunderbird/17.0.7
On 07/30/2013 11:57 AM, Dave Chinner wrote:
> On Tue, Jul 30, 2013 at 11:15:50AM +0800, Gao feng wrote:
>> On 07/29/2013 03:51 PM, Dave Chinner wrote:
>>> http://oss.sgi.com/pipermail/xfs/2013-July/028467.html
>>> Basically, the discussion we are currently having is whether project
>>> IDs should be exposed to user namespaces at all. e.g:
>>> http://oss.sgi.com/pipermail/xfs/2013-July/028497.html
>>> http://oss.sgi.com/pipermail/xfs/2013-July/028551.html
>>> "Basically, until we have worked out *if* project quotas can be used
>>> safely within user namespaces, we need to reject any attempt to use
>>> them from within a user namespace container."
>> yes, seems this v6 patchset allows user in un-init user namespace to setup 
>> proj quota
>> through ioctl, and the projid hasn't been converted to kprojid in this 
>> patchset.
>> Doesn't this will cause user in container has the ability to change the proj 
>> quota
>> which is set by root user in host?
> Dwight just posted v7. can you discuss your concerns in reposnse to
> the relevant patch in that series, please? it's much easier for
> everyone if we keep the discussion int eh one thread ;)

sure, I am compiling  v7 patchset now in order to confirm my misgiving :)


<Prev in Thread] Current Thread [Next in Thread>