[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-02-15 Thread Philipp Wendler
** Also affects: linux-lts-wily (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1531747 Title: overlay: mkdir fails if directory

[Kernel-packages] [Bug 1566471] Re: kernel oops: NULL pointer dereference in nfs_inode_attach_open_context+0x37/0x70 [nfs]

2016-04-13 Thread Philipp Wendler
I also experience this problem using the Xenial kernel 4.4.0-18.34~14.04.1 on Ubuntu 14.04. I can even reproduce it as a non-root user by creating an overlay mount inside a user namespace. After mounting an overlay over an NFS mount, I can successfully traverse existing directories and create,

[Kernel-packages] [Bug 1566471] Re: kernel oops: NULL pointer dereference in nfs_inode_attach_open_context+0x37/0x70 [nfs]

2016-04-26 Thread Philipp Wendler
I tested 4.4.0-22.38_amd64 on Ubuntu 14.04 with an overlay over an NFS4 mount (same situation as in comment #7) and the crash when reading existing files from the lower layer is gone. I did not test overlay over NFS3. I still cannot successfully write to files that exist in the lower layer

[Kernel-packages] [Bug 1793458] Re: Overlayfs in user namespace leaks directory content of inaccessible directories

2018-11-19 Thread Philipp Wendler
Tyler, thanks for the clarification. I have tested it with 4.15.0-42-generic from bionic-proposed and can confirm it is fixed. ** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of Kernel Packages,

[Kernel-packages] [Bug 1793458] Re: Overlayfs in user namespace leaks directory content of inaccessible directories

2018-11-19 Thread Philipp Wendler
I find the demand to test the fix within 5 days, combined with the threat of dropping the patch otherwise, unreasonable. In my original report of this security problem I have already provided a script that allows to reproduce the problem and check if it still exists. Requiring an answer within 5

[Kernel-packages] [Bug 1900141] [NEW] overlay: permission regression in 5.4.0-51.56 due to patches related to CVE-2020-16120

2020-10-16 Thread Philipp Wendler
Public bug reported: We use unprivileged user namespaces with overlay mounts for containers. After recently upgrading our Focal kernels to 5.4.0-51.56 this breaks, one cannot access files through the overlay mount in the container anymore. This is very likely caused by some of the patches that

[Kernel-packages] [Bug 1900141] Re: overlay: permission regression in 5.4.0-51.56 due to patches related to CVE-2020-16120

2021-01-11 Thread Philipp Wendler
Thanks! >> I noticed that in the list of affected packages in the bug metadata >> Bionic is not mentioned. Will the fix also be backported there? > > It depends on which kernel you are talking about. The bionic GA kernel > (4.15) was not affected based on my testing. If you are seeing problems >

[Kernel-packages] [Bug 1900141] Re: overlay: permission regression in 5.4.0-51.56 due to patches related to CVE-2020-16120

2021-01-11 Thread Philipp Wendler
Thanks! I tested it on a Focal machine and the -proposed kernel works. However, I don't have a Groovy machine here, is it necessary for me to test this? I noticed that in the list of affected packages in the bug metadata Bionic is not mentioned. Will the fix also be backported there? ** Tags

[Kernel-packages] [Bug 1900141] Re: overlay: permission regression in 5.4.0-51.56 due to patches related to CVE-2020-16120

2020-11-23 Thread Philipp Wendler
I noticed that the changelog of the kernel package 5.4.0-50.55~18.04.1 for Bionic now also includes the two additional patches, and indeed I can confirm that on Bionic with kernel 5.4.0-54-generic the regression was now also introduced. Is there an update whether it will be possible to solve this

[Kernel-packages] [Bug 1947718] Re: overlay: permission regression in 5.4.0.89.93 due to fix for CVE-2021-3732

2021-10-19 Thread Philipp Wendler
apport information ** Tags added: apport-collected ** Description changed: Since kernel 5.4.0-89.100 on Focal and 4.15.0-159.167 on Bionic I can no longer mount an overlay filesystem over directories like / in a user namespace. With kernel versions 5.4.0-88.99 and 4.15.0-158.166,

[Kernel-packages] [Bug 1947718] ProcCpuinfo.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "ProcCpuinfo.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534262/+files/ProcCpuinfo.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] Lspci.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "Lspci.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534259/+files/Lspci.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1947718

[Kernel-packages] [Bug 1947718] ProcModules.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "ProcModules.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534265/+files/ProcModules.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] Lsusb-v.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "Lsusb-v.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534261/+files/Lsusb-v.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] Lspci-vt.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "Lspci-vt.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534260/+files/Lspci-vt.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] Re: overlay: permission regression in 5.4.0.89.93 due to fix for CVE-2021-3732

2021-10-19 Thread Philipp Wendler
Status set to "Confirmed" as requested by the bot after uploading logs (although I did upload them when creating the issue as well...). -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] WifiSyslog.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "WifiSyslog.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534267/+files/WifiSyslog.txt ** Changed in: linux (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of Kernel Packages,

[Kernel-packages] [Bug 1947718] UdevDb.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "UdevDb.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534266/+files/UdevDb.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] ProcCpuinfoMinimal.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "ProcCpuinfoMinimal.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534263/+files/ProcCpuinfoMinimal.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] ProcInterrupts.txt

2021-10-19 Thread Philipp Wendler
apport information ** Attachment added: "ProcInterrupts.txt" https://bugs.launchpad.net/bugs/1947718/+attachment/5534264/+files/ProcInterrupts.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1947718] [NEW] overlay: permission regression in 5.4.0.89.93 due to fix for CVE-2021-3732

2021-10-19 Thread Philipp Wendler
Public bug reported: Since kernel 5.4.0-89.100 on Focal and 4.15.0-159.167 on Bionic I can no longer mount an overlay filesystem over directories like / in a user namespace. With kernel versions 5.4.0-88.99 and 4.15.0-158.166, respectively, this still works. An easy way to test this is the

[Kernel-packages] [Bug 1947718] Re: overlay: permission regression in 5.4.0.89.93 due to fix for CVE-2021-3732

2022-01-10 Thread Philipp Wendler
This is a kernel regression and now almost three months old. Could somebody please have a look? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1947718 Title: overlay: permission

[Kernel-packages] [Bug 1947718] Re: overlay: permission regression in 5.4.0.89.93 due to fix for CVE-2021-3732

2022-06-13 Thread Philipp Wendler
I now tested with newer kernels: The regression is still present in 5.15.0-33-generic from the hwe-edge package for Ubuntu 20.04. I also tested kernels from the Ubuntu Mainline Kernel Archive. It works with 5.13.0-051300-generic and fails with 5.14.0-051400-generic and also still with