Forum | Documentation | Website | Blog

Skip to content
Snippets Groups Projects
Unverified Commit a2d2329e authored by Christian Brauner's avatar Christian Brauner
Browse files

ima: handle idmapped mounts

IMA does sometimes access the inode's i_uid and compares it against the
rules' fowner. Enable IMA to handle idmapped mounts by passing down the
mount's user namespace. We simply make use of the helpers we introduced
before. If the initial user namespace is passed nothing changes so
non-idmapped mounts will see identical behavior as before.

Link: https://lore.kernel.org/r/20210121131959.646623-27-christian.brauner@ubuntu.com


Signed-off-by: default avatarChristian Brauner <christian.brauner@ubuntu.com>
parent 3cee6079
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment