[PATCH 02/11] mtd: Check permissions towards mtd block device inode when mounting

Richard Weinberger richard.weinberger at gmail.com
Fri Dec 22 21:06:13 UTC 2017


Dongsu,

On Fri, Dec 22, 2017 at 3:32 PM, Dongsu Park <dongsu at kinvolk.io> wrote:
> From: Seth Forshee <seth.forshee at canonical.com>
>
> Unprivileged users should not be able to mount mtd block devices
> when they lack sufficient privileges towards the block device
> inode.  Update mount_mtd() to validate that the user has the
> required access to the inode at the specified path. The check
> will be skipped for CAP_SYS_ADMIN, so privileged mounts will
> continue working as before.

What is the big picture of this?
Can in future an unprivileged user just mount UBIFS?
Please note that UBIFS sits on top of a character device and not a block device.

-- 
Thanks,
//richard


More information about the Containers mailing list