]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
nsfs: tighten permission checks for handle opening
authorChristian Brauner <brauner@kernel.org>
Thu, 26 Feb 2026 13:50:10 +0000 (14:50 +0100)
committerChristian Brauner <brauner@kernel.org>
Fri, 27 Feb 2026 21:00:11 +0000 (22:00 +0100)
commitd2324a9317f00013facb0ba00b00440e19d2af5e
treef4be79d9f7824576062e4ecc512e0e96382cc849
parente6b899f08066e744f89df16ceb782e06868bd148
nsfs: tighten permission checks for handle opening

Even privileged services should not necessarily be able to see other
privileged service's namespaces so they can't leak information to each
other. Use may_see_all_namespaces() helper that centralizes this policy
until the nstree adapts.

Link: https://patch.msgid.link/20260226-work-visibility-fixes-v1-2-d2c2853313bd@kernel.org
Fixes: 5222470b2fbb ("nsfs: support file handles")
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Cc: stable@kernel.org # v6.18+
Signed-off-by: Christian Brauner <brauner@kernel.org>
fs/nsfs.c