diff options
author | Eric W. Biederman <ebiederm@xmission.com> | 2017-09-18 17:58:08 -0500 |
---|---|---|
committer | Eric W. Biederman <ebiederm@xmission.com> | 2018-05-24 12:02:25 -0500 |
commit | bc6155d1326092f4c29fe05a32b614249620d88e (patch) | |
tree | d36853f7e280a4dff8d653981ce71193218c77b7 /Documentation/auxdisplay | |
parent | 0031181c49ca94b14b11f08e447f40c6ebc842a4 (diff) |
fs: Allow superblock owner to access do_remount_sb()
Superblock level remounts are currently restricted to global
CAP_SYS_ADMIN, as is the path for changing the root mount to
read only on umount. Loosen both of these permission checks to
also allow CAP_SYS_ADMIN in any namespace which is privileged
towards the userns which originally mounted the filesystem.
Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
Acked-by: "Eric W. Biederman" <ebiederm@xmission.com>
Acked-by: Serge Hallyn <serge@hallyn.com>
Acked-by: Christian Brauner <christian@brauner.io>
Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Diffstat (limited to 'Documentation/auxdisplay')
0 files changed, 0 insertions, 0 deletions