[PATCH v2 0/2] openat2: reject RESOLVE_BENEATH|RESOLVE_IN_ROOT

Aleksa Sarai cyphar at cyphar.com
Tue Oct 27 23:50:42 UTC 2020


This was an oversight in the original implementation, as it makes no
sense to specify both scoping flags to the same openat2(2) invocation
(before this patch, the result of such an invocation was equivalent to
RESOLVE_IN_ROOT being ignored).

This is a userspace-visible ABI change, but the only user of openat2(2)
at the moment is LXC which doesn't specify both flags and so no
userspace programs will break as a result.

Changelog:
  v2: Split patch so as to separate selftest changes. [Shuah Khan]
  v1: <https://lore.kernel.org/lkml/20201007103608.17349-1-cyphar@cyphar.com/>

Aleksa Sarai (2):
  openat2: reject RESOLVE_BENEATH|RESOLVE_IN_ROOT
  selftests: openat2: add RESOLVE_ conflict test

 fs/open.c                                      | 4 ++++
 tools/testing/selftests/openat2/openat2_test.c | 8 +++++++-
 2 files changed, 11 insertions(+), 1 deletion(-)

-- 
2.29.0



More information about the Containers mailing list