Skip to content

Commit ba7ed06

Browse files
hallynheftig
authored andcommitted
add sysctl to allow disabling unprivileged CLONE_NEWUSER
This is a short-term patch. Unprivileged use of CLONE_NEWUSER is certainly an intended feature of user namespaces. However for at least saucy we want to make sure that, if any security issues are found, we have a fail-safe. [bwh: Remove unneeded binary sysctl bits] [bwh: Keep this sysctl, but change the default to enabled] [heftig: correct commit subject to reduce confusion] [heftig: for 6.17, move all code into kernel/fork.c]
1 parent 58e7295 commit ba7ed06

1 file changed

Lines changed: 24 additions & 0 deletions

File tree

‎kernel/fork.c‎

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -127,6 +127,12 @@
127127

128128
#include
129129

130+
#ifdef CONFIG_USER_NS
131+
static int unprivileged_userns_clone = 1;
132+
#else
133+
#define unprivileged_userns_clone 1
134+
#endif
135+
130136
/*
131137
* Minimum number of threads to boot the kernel
132138
*/
@@ -2093,6 +2099,11 @@ __latent_entropy struct task_struct *copy_process(
20932099
return ERR_PTR(-EPERM);
20942100
}
20952101

2102+
if ((clone_flags & CLONE_NEWUSER) && !unprivileged_userns_clone) {
2103+
if (!capable(CAP_SYS_ADMIN))
2104+
return ERR_PTR(-EPERM);
2105+
}
2106+
20962107
/*
20972108
* Force any signals received before this point to be delivered
20982109
* before the fork happens. Collect up signals sent to multiple
@@ -3163,6 +3174,10 @@ static int check_unshare_flags(unsigned long unshare_flags)
31633174
if (!current_is_single_threaded())
31643175
return -EINVAL;
31653176
}
3177+
if ((unshare_flags & CLONE_NEWUSER) && !unprivileged_userns_clone) {
3178+
if (!capable(CAP_SYS_ADMIN))
3179+
return -EPERM;
3180+
}
31663181

31673182
return 0;
31683183
}
@@ -3398,6 +3413,15 @@ static const struct ctl_table fork_sysctl_table[] = {
33983413
.mode = 0644,
33993414
.proc_handler = sysctl_max_threads,
34003415
},
3416+
#ifdef CONFIG_USER_NS
3417+
{
3418+
.procname = "unprivileged_userns_clone",
3419+
.data = &unprivileged_userns_clone,
3420+
.maxlen = sizeof(int),
3421+
.mode = 0644,
3422+
.proc_handler = proc_dointvec,
3423+
},
3424+
#endif
34013425
};
34023426

34033427
static int __init init_fork_sysctl(void)

0 commit comments

Comments
 (0)