[PATCH v4 0/4] Introduce security_create_user_ns()

Eric W. Biederman ebiederm at xmission.com
Mon Aug 8 19:26:04 UTC 2022


Paul Moore <paul at paul-moore.com> writes:

>> I did provide constructive feedback.  My feedback to his problem
>> was to address the real problem of bugs in the kernel.
>
> We've heard from several people who have use cases which require
> adding LSM-level access controls and observability to user namespace
> creation.  This is the problem we are trying to solve here; if you do
> not like the approach proposed in this patchset please suggest another
> implementation that allows LSMs visibility into user namespace
> creation.

Please stop, ignoring my feedback, not detailing what problem or
problems you are actually trying to be solved, and threatening to merge
code into files that I maintain that has the express purpose of breaking
my users.

You just artificially constrained the problems, so that no other
solution is acceptable.  On that basis alone I am object to this whole
approach to steam roll over me and my code.

Eric



More information about the Linux-security-module-archive mailing list