From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-ot0-f173.google.com ([74.125.82.173]:46965 "EHLO mail-ot0-f173.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752563AbeEKN7B (ORCPT ); Fri, 11 May 2018 09:59:01 -0400 Received: by mail-ot0-f173.google.com with SMTP id t1-v6so6310103ott.13 for ; Fri, 11 May 2018 06:59:00 -0700 (PDT) MIME-Version: 1.0 In-Reply-To: <20180511093707.GA1403@comp-core-i7-2640m-0182e6> References: <20180511093707.GA1403@comp-core-i7-2640m-0182e6> From: Jann Horn Date: Fri, 11 May 2018 15:58:39 +0200 Message-ID: Subject: Re: [PATCH v5 7/7] proc: add option to mount only a pids subset To: Alexey Gladkov Cc: Kees Cook , Andy Lutomirski , Andrew Morton , linux-fsdevel@vger.kernel.org, kernel list , Kernel Hardening , linux-security-module , Linux API , Greg Kroah-Hartman , Alexander Viro , Akinobu Mita , Oleg Nesterov , Jeff Layton , Ingo Molnar , Alexey Dobriyan , "Eric W. Biederman" , Linus Torvalds , aniel Micay , Jonathan Corbet , bfields@fieldses.org, Stephen Rothwell , Solar Designer , "Dmitry V. Levin" , Djalal Harouni Content-Type: text/plain; charset="UTF-8" Sender: linux-fsdevel-owner@vger.kernel.org List-ID: On Fri, May 11, 2018 at 11:37 AM, Alexey Gladkov wrote: > This allows to hide all files and directories in the procfs that are not > related to tasks. /proc/$pid/net and /proc/$pid/task/$tid/net aren't in scope for this protection, even though they contain information about the whole network namespace of the task, right?