Re: [PATCH v10 0/7] proc: subset=pid: Relax check of mount visibility
Aleksa Sarai <[email protected]> Tue, 28 Apr 2026 08:34:51 +1000
| Newsgroups | dev.linux.lists.containers,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
--wgwy7sdqlg4y7yc5 Content-Type: text/plain; protected-headers=v1; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: [PATCH v10 0/7] proc: subset=pid: Relax check of mount visibility MIME-Version: 1.0 On 2026-04-27, Alexey Gladkov <[email protected]> wrote: > When mounting procfs with the subset=3Dpids option, all static files beco= me > unavailable and only the dynamic part with information about pids is acce= ssible. >=20 > In this case, there is no point in imposing additional restrictions on the > visibility of the entire filesystem for the mounter. Everything that can = be > hidden in procfs is already inaccessible. >=20 > Currently, these restrictions prevent pidfs from being mounted inside roo= tless > containers, as almost all container implementations override part of proc= fs to > hide certain directories. Relaxing these restrictions will allow pidfs to= be > used in nested containerization. Aside from one minor nit about invalf, looks great! Feel free to take my Reviewed-by: Aleksa Sarai <[email protected]> --=20 Aleksa Sarai https://www.cyphar.com/ --wgwy7sdqlg4y7yc5 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iJEEABYKADkWIQS2TklVsp+j1GPyqQYol/rSt+lEbwUCae/kixsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMiwyLDIACgkQKJf60rfpRG/VuQD/UPsI24qwGwwXdLVWZyr3 Ho7Oa8rJ4AqYST3oMyGZWtABAMSTa2tsJV9JFcDqPhzE4BB5TERCr0fAiB3xx5uU OXUB =TF0D -----END PGP SIGNATURE----- --wgwy7sdqlg4y7yc5--