Skip to content

Commit 50ec499

Browse files
legionusakpm00
authored andcommitted
sysctl: allow change system v ipc sysctls inside ipc namespace
Patch series "Allow to change ipc/mq sysctls inside ipc namespace", v3. Right now ipc and mq limits count as per ipc namespace, but only real root can change them. By default, the current values of these limits are such that it can only be reduced. Since only root can change the values, it is impossible to reduce these limits in the rootless container. We can allow limit changes within ipc namespace because mq parameters are limited by RLIMIT_MSGQUEUE and ipc parameters are not limited to anything other than cgroups. This patch (of 3): Rootless containers are not allowed to modify kernel IPC parameters. All default limits are set to such high values that in fact there are no limits at all. All limits are not inherited and are initialized to default values when a new ipc_namespace is created. For new ipc_namespace: size_t ipc_ns.shm_ctlmax = SHMMAX; // (ULONG_MAX - (1UL << 24)) size_t ipc_ns.shm_ctlall = SHMALL; // (ULONG_MAX - (1UL << 24)) int ipc_ns.shm_ctlmni = IPCMNI; // (1 << 15) int ipc_ns.shm_rmid_forced = 0; unsigned int ipc_ns.msg_ctlmax = MSGMAX; // 8192 unsigned int ipc_ns.msg_ctlmni = MSGMNI; // 32000 unsigned int ipc_ns.msg_ctlmnb = MSGMNB; // 16384 The shm_tot (total amount of shared pages) has also ceased to be global, it is located in ipc_namespace and is not inherited from anywhere. In such conditions, it cannot be said that these limits limit anything. The real limiter for them is cgroups. If we allow rootless containers to change these parameters, then it can only be reduced. Link: https://lkml.kernel.org/r/cover.1705333426.git.legion@kernel.org Link: https://lkml.kernel.org/r/d2f4603305cbfed58a24755aa61d027314b73a45.1705333426.git.legion@kernel.org Signed-off-by: Alexey Gladkov <legion@kernel.org> Signed-off-by: Eric W. Biederman <ebiederm@xmission.com> Link: https://lkml.kernel.org/r/e2d84d3ec0172cfff759e6065da84ce0cc2736f8.1663756794.git.legion@kernel.org Cc: Christian Brauner <brauner@kernel.org> Cc: Joel Granados <joel.granados@gmail.com> Cc: Kees Cook <keescook@chromium.org> Cc: Luis Chamberlain <mcgrof@kernel.org> Cc: Manfred Spraul <manfred@colorfullife.com> Cc: Davidlohr Bueso <dave@stgolabs.net> Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
1 parent c641722 commit 50ec499

File tree

1 file changed

+35
-2
lines changed

1 file changed

+35
-2
lines changed

ipc/ipc_sysctl.c

+35-2
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@
1414
#include <linux/ipc_namespace.h>
1515
#include <linux/msg.h>
1616
#include <linux/slab.h>
17+
#include <linux/cred.h>
1718
#include "util.h"
1819

1920
static int proc_ipc_dointvec_minmax_orphans(struct ctl_table *table, int write,
@@ -190,25 +191,57 @@ static int set_is_seen(struct ctl_table_set *set)
190191
return &current->nsproxy->ipc_ns->ipc_set == set;
191192
}
192193

194+
static void ipc_set_ownership(struct ctl_table_header *head,
195+
struct ctl_table *table,
196+
kuid_t *uid, kgid_t *gid)
197+
{
198+
struct ipc_namespace *ns =
199+
container_of(head->set, struct ipc_namespace, ipc_set);
200+
201+
kuid_t ns_root_uid = make_kuid(ns->user_ns, 0);
202+
kgid_t ns_root_gid = make_kgid(ns->user_ns, 0);
203+
204+
*uid = uid_valid(ns_root_uid) ? ns_root_uid : GLOBAL_ROOT_UID;
205+
*gid = gid_valid(ns_root_gid) ? ns_root_gid : GLOBAL_ROOT_GID;
206+
}
207+
193208
static int ipc_permissions(struct ctl_table_header *head, struct ctl_table *table)
194209
{
195210
int mode = table->mode;
196211

197212
#ifdef CONFIG_CHECKPOINT_RESTORE
198-
struct ipc_namespace *ns = current->nsproxy->ipc_ns;
213+
struct ipc_namespace *ns =
214+
container_of(head->set, struct ipc_namespace, ipc_set);
199215

200216
if (((table->data == &ns->ids[IPC_SEM_IDS].next_id) ||
201217
(table->data == &ns->ids[IPC_MSG_IDS].next_id) ||
202218
(table->data == &ns->ids[IPC_SHM_IDS].next_id)) &&
203219
checkpoint_restore_ns_capable(ns->user_ns))
204220
mode = 0666;
221+
else
205222
#endif
206-
return mode;
223+
{
224+
kuid_t ns_root_uid;
225+
kgid_t ns_root_gid;
226+
227+
ipc_set_ownership(head, table, &ns_root_uid, &ns_root_gid);
228+
229+
if (uid_eq(current_euid(), ns_root_uid))
230+
mode >>= 6;
231+
232+
else if (in_egroup_p(ns_root_gid))
233+
mode >>= 3;
234+
}
235+
236+
mode &= 7;
237+
238+
return (mode << 6) | (mode << 3) | mode;
207239
}
208240

209241
static struct ctl_table_root set_root = {
210242
.lookup = set_lookup,
211243
.permissions = ipc_permissions,
244+
.set_ownership = ipc_set_ownership,
212245
};
213246

214247
bool setup_ipc_sysctls(struct ipc_namespace *ns)

0 commit comments

Comments
 (0)