From: Ville Herva <vherva@mail.niksula.cs.hut.fi>
To: viro@math.psu.edu
Cc: linux-kernel@vger.kernel.org
Subject: mount --bind and -o [re: nosuid/noexec/nodev handling]
Date: Sun, 14 Oct 2001 18:59:08 +0300 [thread overview]
Message-ID: <20011014185908.P1074@niksula.cs.hut.fi> (raw)
On 2001-09-12 17:30:22 you wrote:
>
> nosuid, noexec and nodev are made vfsmount flags (instead of
> superblock ones). Places that used to check them switched to checking
> vfsmount->mnt_flags. get_filesystem_info() updated, ditto for
> do_add_mount() and do_remount().
>
> As the result, these flags are per-mountpoint now. E.g. we can turn them
> on and off for arbitrary subtree:
>
> mount --bind /home/luser /home/luser
> mount -o remount,noexec /home/luser
>
> will turn noexec on for subtree at /hom/luser without affecting the rest
> /of home. Other obvious applications is mounting a filesystem nosuid for
> chroot jail and normally outside of it, yodda, yodda.
>
> Patch is completely straightforward. Works here and it had been in ac for
> -a month (i.e. since 2.4.8-ac2). Please, apply.
Ummh, is there a reason for this behaviour?
$ mount --bind -o noexec /bin /home/sftp/bin
$ mount
(...)
/bin on /home/sftp/bin type none (rw,noexec,bind)
$ cd /home/sftp/bin
$ ./uname -a
Linux babbage 2.4.10-ac10 #4 SMP Wed Oct 10 11:39:11 EEST 2001 i686 unknown
$ mount -o remount,noexec /home/sftp/bin
$ mount
(...)
/bin on /home/sftp/bin type none (rw,noexec,bind)
$ ./uname -a
zsh: permission denied: ./uname
That seems like a bug to me. At very least, mount shouldn't report noexec if
the mount point isn't. Or am I missing something?
Further:
$ mount --bind -o ro /bin /home/sftp/bin
$ mount -o remount,ro,nosuid /home/sftp/bin
$ mount: /home/sftp/bin is busy
$ mount
(...)
/bin on /home/sftp/bin type none (ro,bind)
$ cd /home/sftp/bin
$ touch asdakhsdhdh
$ ls asdakhsdhdh
asdakhsdhdh
So I suppose ro (umask, some others as well) is not supported for --bind
mounted mount points? Would it be possible to have mount to report error if
non-functional -o options are passed to it?
And btw, thanks. --bind is a damn cool feature to have.
-- v --
v@iki.fi
next reply other threads:[~2001-10-14 15:59 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-10-14 15:59 Ville Herva [this message]
2001-10-14 16:06 ` Alexander Viro
2001-10-14 16:12 ` Ville Herva
2001-10-14 16:20 ` Alexander Viro
2001-10-14 17:09 ` Ville Herva
2001-10-14 17:23 ` Ville Herva
2001-10-14 17:32 ` Alexander Viro
2001-10-14 16:22 ` Ville Herva
2001-10-14 16:29 ` Alexander Viro
2001-10-14 17:44 ` Ville Herva
2001-10-14 23:37 ` Bernd Eckenfels
2001-10-14 23:48 ` Alexander Viro
2001-10-15 6:53 ` Ville Herva
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20011014185908.P1074@niksula.cs.hut.fi \
--to=vherva@mail.niksula.cs.hut.fi \
--cc=linux-kernel@vger.kernel.org \
--cc=viro@math.psu.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®