From: "Serge E. Hallyn" <serge@hallyn.com>
To: "Eric W. Biederman" <ebiederm@xmission.com>
Cc: Linux Containers <containers@lists.linux-foundation.org>,
Andy Lutomirski <luto@amacapital.net>, Jann Horn <jann@thejh.net>,
Kees Cook <keescook@chromium.org>,
Nikolay Borisov <kernel@kyup.com>,
"Serge E. Hallyn" <serge@hallyn.com>,
Seth Forshee <seth.forshee@canonical.com>,
linux-fsdevel@vger.kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-api@vger.kernel.org
Subject: Re: [PATCH v2 07/10] ipcns: Add a limit on the number of ipc namespaces
Date: Mon, 25 Jul 2016 18:10:29 -0500 [thread overview]
Message-ID: <20160725231029.GE26841@mail.hallyn.com> (raw)
In-Reply-To: <20160721164014.17534-7-ebiederm@xmission.com>
Quoting Eric W. Biederman (ebiederm@xmission.com):
> Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Acked-by: Serge Hallyn <serge@hallyn.com>
> ---
> include/linux/user_namespace.h | 1 +
> ipc/namespace.c | 42 +++++++++++++++++++++++++++++++-----------
> kernel/user_namespace.c | 1 +
> 3 files changed, 33 insertions(+), 11 deletions(-)
>
> diff --git a/include/linux/user_namespace.h b/include/linux/user_namespace.h
> index bed2506081fe..367cf08ff63d 100644
> --- a/include/linux/user_namespace.h
> +++ b/include/linux/user_namespace.h
> @@ -26,6 +26,7 @@ enum ucounts {
> UCOUNT_USER_NAMESPACES,
> UCOUNT_PID_NAMESPACES,
> UCOUNT_UTS_NAMESPACES,
> + UCOUNT_IPC_NAMESPACES,
> UCOUNT_COUNTS,
> };
>
> diff --git a/ipc/namespace.c b/ipc/namespace.c
> index 04cb07eb81f1..3996a1e41a1d 100644
> --- a/ipc/namespace.c
> +++ b/ipc/namespace.c
> @@ -16,33 +16,42 @@
>
> #include "util.h"
>
> +static bool inc_ipc_namespaces(struct user_namespace *ns)
> +{
> + return inc_ucount(ns, UCOUNT_IPC_NAMESPACES);
> +}
> +
> +static void dec_ipc_namespaces(struct user_namespace *ns)
> +{
> + dec_ucount(ns, UCOUNT_IPC_NAMESPACES);
> +}
> +
> static struct ipc_namespace *create_ipc_ns(struct user_namespace *user_ns,
> struct ipc_namespace *old_ns)
> {
> struct ipc_namespace *ns;
> int err;
>
> + err = -ENFILE;
> + if (!inc_ipc_namespaces(user_ns))
> + goto fail;
> +
> + err = -ENOMEM;
> ns = kmalloc(sizeof(struct ipc_namespace), GFP_KERNEL);
> if (ns == NULL)
> - return ERR_PTR(-ENOMEM);
> + goto fail_dec;
>
> err = ns_alloc_inum(&ns->ns);
> - if (err) {
> - kfree(ns);
> - return ERR_PTR(err);
> - }
> + if (err)
> + goto fail_free;
> ns->ns.ops = &ipcns_operations;
>
> atomic_set(&ns->count, 1);
> ns->user_ns = get_user_ns(user_ns);
>
> err = mq_init_ns(ns);
> - if (err) {
> - put_user_ns(ns->user_ns);
> - ns_free_inum(&ns->ns);
> - kfree(ns);
> - return ERR_PTR(err);
> - }
> + if (err)
> + goto fail_put;
> atomic_inc(&nr_ipc_ns);
>
> sem_init_ns(ns);
> @@ -50,6 +59,16 @@ static struct ipc_namespace *create_ipc_ns(struct user_namespace *user_ns,
> shm_init_ns(ns);
>
> return ns;
> +
> +fail_put:
> + put_user_ns(ns->user_ns);
> + ns_free_inum(&ns->ns);
> +fail_free:
> + kfree(ns);
> +fail_dec:
> + dec_ipc_namespaces(user_ns);
> +fail:
> + return ERR_PTR(err);
> }
>
> struct ipc_namespace *copy_ipcs(unsigned long flags,
> @@ -98,6 +117,7 @@ static void free_ipc_ns(struct ipc_namespace *ns)
> shm_exit_ns(ns);
> atomic_dec(&nr_ipc_ns);
>
> + dec_ipc_namespaces(ns->user_ns);
> put_user_ns(ns->user_ns);
> ns_free_inum(&ns->ns);
> kfree(ns);
> diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c
> index 6b205c24e888..060d3e099f87 100644
> --- a/kernel/user_namespace.c
> +++ b/kernel/user_namespace.c
> @@ -79,6 +79,7 @@ static struct ctl_table userns_table[] = {
> UCOUNT_ENTRY("max_user_namespaces"),
> UCOUNT_ENTRY("max_pid_namespaces"),
> UCOUNT_ENTRY("max_uts_namespaces"),
> + UCOUNT_ENTRY("max_ipc_namespaces"),
> { }
> };
> #endif /* CONFIG_SYSCTL */
> --
> 2.8.3
next prev parent reply other threads:[~2016-07-25 23:10 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <8737n5dscy.fsf@x220.int.ebiederm.org>
2016-07-21 16:39 ` [PATCH v2 00/10] userns: sysctl limits for namespaces Eric W. Biederman
2016-07-21 16:40 ` [PATCH v2 01/10] sysctl: Stop implicitly passing current into sysctl_table_root.lookup Eric W. Biederman
2016-07-21 16:40 ` [PATCH v2 02/10] userns: Add per user namespace sysctls Eric W. Biederman
2016-07-26 0:02 ` Eric W. Biederman
2016-07-26 0:24 ` David Miller
2016-07-26 0:44 ` Eric W. Biederman
2016-07-26 2:58 ` David Miller
2016-07-26 4:00 ` Eric W. Biederman
2016-07-21 16:40 ` [PATCH v2 03/10] userns: Add a limit on the number of user namespaces Eric W. Biederman
2016-07-25 23:05 ` Serge E. Hallyn
2016-07-21 16:40 ` [PATCH v2 04/10] userns: Generalize the user namespace count into ucount Eric W. Biederman
2016-07-25 23:09 ` Serge E. Hallyn
2016-07-21 16:40 ` [PATCH v2 05/10] pidns: Add a limit on the number of pid namespaces Eric W. Biederman
2016-07-25 23:09 ` Serge E. Hallyn
2016-07-21 16:40 ` [PATCH v2 06/10] utsns: Add a limit on the number of uts namespaces Eric W. Biederman
2016-07-25 23:09 ` Serge E. Hallyn
2016-07-21 16:40 ` [PATCH v2 07/10] ipcns: Add a limit on the number of ipc namespaces Eric W. Biederman
2016-07-25 23:10 ` Serge E. Hallyn [this message]
2016-07-21 16:40 ` [PATCH v2 08/10] cgroupns: Add a limit on the number of cgroup namespaces Eric W. Biederman
2016-07-25 23:12 ` Serge E. Hallyn
2016-07-21 16:40 ` [PATCH v2 09/10] netns: Add a limit on the number of net namespaces Eric W. Biederman
2016-07-25 23:13 ` Serge E. Hallyn
2016-07-26 6:01 ` Andrei Vagin
2016-07-26 20:00 ` Eric W. Biederman
2016-07-21 16:40 ` [PATCH v2 10/10] mntns: Add a limit on the number of mount namespaces Eric W. Biederman
2016-07-25 23:15 ` Serge E. Hallyn
2016-07-22 13:33 ` [PATCH v2 00/10] userns: sysctl limits for namespaces Colin Walters
2016-07-22 18:45 ` Eric W. Biederman
2016-07-22 21:46 ` Kees Cook
2016-07-23 2:11 ` Eric W. Biederman
2016-07-26 10:27 ` Michael Kerrisk (man-pages)
2016-07-26 15:14 ` Eric W. Biederman
2016-07-26 10:30 ` Michael Kerrisk (man-pages)
2016-07-26 15:06 ` Eric W. Biederman
2016-07-26 16:52 ` Kees Cook
2016-07-26 17:29 ` Michael Kerrisk (man-pages)
2016-07-26 20:44 ` Kees Cook
2016-08-08 21:16 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160725231029.GE26841@mail.hallyn.com \
--to=serge@hallyn.com \
--cc=containers@lists.linux-foundation.org \
--cc=ebiederm@xmission.com \
--cc=jann@thejh.net \
--cc=keescook@chromium.org \
--cc=kernel@kyup.com \
--cc=linux-api@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@amacapital.net \
--cc=netdev@vger.kernel.org \
--cc=seth.forshee@canonical.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).