projects
/
platform
/
adaptation
/
renesas_rcar
/
renesas_kernel.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
userns: Restrict when proc and sysfs can be mounted
[platform/adaptation/renesas_rcar/renesas_kernel.git]
/
fs
/
sysfs
/
mount.c
diff --git
a/fs/sysfs/mount.c
b/fs/sysfs/mount.c
index
8d924b5
..
afd8327
100644
(file)
--- a/
fs/sysfs/mount.c
+++ b/
fs/sysfs/mount.c
@@
-19,6
+19,7
@@
#include <linux/module.h>
#include <linux/magic.h>
#include <linux/slab.h>
#include <linux/module.h>
#include <linux/magic.h>
#include <linux/slab.h>
+#include <linux/user_namespace.h>
#include "sysfs.h"
#include "sysfs.h"
@@
-111,6
+112,9
@@
static struct dentry *sysfs_mount(struct file_system_type *fs_type,
struct super_block *sb;
int error;
struct super_block *sb;
int error;
+ if (!(flags & MS_KERNMOUNT) && !current_user_ns()->may_mount_sysfs)
+ return ERR_PTR(-EPERM);
+
info = kzalloc(sizeof(*info), GFP_KERNEL);
if (!info)
return ERR_PTR(-ENOMEM);
info = kzalloc(sizeof(*info), GFP_KERNEL);
if (!info)
return ERR_PTR(-ENOMEM);