• Andrey Vagin's avatar
    proc: mount proc with minimal permissions · 2a0c8db7
    Andrey Vagin authored
    Eric wants to restrict permissions for proc mounts in a non-root userns
    according with proc mounts in the root userns.
    
    Author: Eric W. Biederman <ebiederm@xmission.com>
    Date:   Fri May 8 23:49:47 2015 -0500
    
        mnt: Modify fs_fully_visible to deal with locked ro nodev and atime
    
        Ignore an existing mount if the locked readonly, nodev or atime
        attributes are less permissive than the desired attributes
        of the new mount.
    ...
    Signed-off-by: 's avatarAndrey Vagin <avagin@openvz.org>
    Signed-off-by: 's avatarPavel Emelyanov <xemul@parallels.com>
    2a0c8db7
ns.c 10.5 KB