[PATCH v3 20/21] fuse: Restrict allow_other to the superblock's namespace or a descendant

2016-04-22 Thread Seth Forshee
Unprivileged users are normally restricted from mounting with the allow_other option by system policy, but this could be bypassed for a mount done with user namespace root permissions. In such cases allow_other should not allow users outside the userns to access the mount as doing so would give

[PATCH v3 20/21] fuse: Restrict allow_other to the superblock's namespace or a descendant

2016-04-22 Thread Seth Forshee
Unprivileged users are normally restricted from mounting with the allow_other option by system policy, but this could be bypassed for a mount done with user namespace root permissions. In such cases allow_other should not allow users outside the userns to access the mount as doing so would give