Lines Matching refs:ns

30 				struct user_namespace *ns, int cap_setid,
62 struct user_namespace *ns, *parent_ns = new->user_ns; in create_user_ns() local
87 ns = kmem_cache_zalloc(user_ns_cachep, GFP_KERNEL); in create_user_ns()
88 if (!ns) in create_user_ns()
91 ret = ns_alloc_inum(&ns->ns); in create_user_ns()
93 kmem_cache_free(user_ns_cachep, ns); in create_user_ns()
96 ns->ns.ops = &userns_operations; in create_user_ns()
98 atomic_set(&ns->count, 1); in create_user_ns()
100 ns->parent = parent_ns; in create_user_ns()
101 ns->level = parent_ns->level + 1; in create_user_ns()
102 ns->owner = owner; in create_user_ns()
103 ns->group = group; in create_user_ns()
107 ns->flags = parent_ns->flags; in create_user_ns()
110 set_cred_user_ns(new, ns); in create_user_ns()
113 init_rwsem(&ns->persistent_keyring_register_sem); in create_user_ns()
138 void free_user_ns(struct user_namespace *ns) in free_user_ns() argument
143 parent = ns->parent; in free_user_ns()
145 key_put(ns->persistent_keyring_register); in free_user_ns()
147 ns_free_inum(&ns->ns); in free_user_ns()
148 kmem_cache_free(user_ns_cachep, ns); in free_user_ns()
149 ns = parent; in free_user_ns()
239 kuid_t make_kuid(struct user_namespace *ns, uid_t uid) in make_kuid() argument
242 return KUIDT_INIT(map_id_down(&ns->uid_map, uid)); in make_kuid()
307 kgid_t make_kgid(struct user_namespace *ns, gid_t gid) in make_kgid() argument
310 return KGIDT_INIT(map_id_down(&ns->gid_map, gid)); in make_kgid()
374 kprojid_t make_kprojid(struct user_namespace *ns, projid_t projid) in make_kprojid() argument
377 return KPROJIDT_INIT(map_id_down(&ns->projid_map, projid)); in make_kprojid()
432 struct user_namespace *ns = seq->private; in uid_m_show() local
438 if ((lower_ns == ns) && lower_ns->parent) in uid_m_show()
453 struct user_namespace *ns = seq->private; in gid_m_show() local
459 if ((lower_ns == ns) && lower_ns->parent) in gid_m_show()
474 struct user_namespace *ns = seq->private; in projid_m_show() local
480 if ((lower_ns == ns) && lower_ns->parent) in projid_m_show()
507 struct user_namespace *ns = seq->private; in uid_m_start() local
509 return m_start(seq, ppos, &ns->uid_map); in uid_m_start()
514 struct user_namespace *ns = seq->private; in gid_m_start() local
516 return m_start(seq, ppos, &ns->gid_map); in gid_m_start()
521 struct user_namespace *ns = seq->private; in projid_m_start() local
523 return m_start(seq, ppos, &ns->projid_map); in projid_m_start()
601 struct user_namespace *ns = seq->private; in map_write() local
638 if (cap_valid(cap_setid) && !file_ns_capable(file, ns, CAP_SYS_ADMIN)) in map_write()
726 if (!new_idmap_permitted(file, ns, cap_setid, &new_map)) in map_write()
768 struct user_namespace *ns = seq->private; in proc_uid_map_write() local
771 if (!ns->parent) in proc_uid_map_write()
774 if ((seq_ns != ns) && (seq_ns != ns->parent)) in proc_uid_map_write()
778 &ns->uid_map, &ns->parent->uid_map); in proc_uid_map_write()
785 struct user_namespace *ns = seq->private; in proc_gid_map_write() local
788 if (!ns->parent) in proc_gid_map_write()
791 if ((seq_ns != ns) && (seq_ns != ns->parent)) in proc_gid_map_write()
795 &ns->gid_map, &ns->parent->gid_map); in proc_gid_map_write()
802 struct user_namespace *ns = seq->private; in proc_projid_map_write() local
805 if (!ns->parent) in proc_projid_map_write()
808 if ((seq_ns != ns) && (seq_ns != ns->parent)) in proc_projid_map_write()
813 &ns->projid_map, &ns->parent->projid_map); in proc_projid_map_write()
817 struct user_namespace *ns, int cap_setid, in new_idmap_permitted() argument
825 uid_eq(ns->owner, cred->euid)) { in new_idmap_permitted()
828 kuid_t uid = make_kuid(ns->parent, id); in new_idmap_permitted()
832 kgid_t gid = make_kgid(ns->parent, id); in new_idmap_permitted()
833 if (!(ns->flags & USERNS_SETGROUPS_ALLOWED) && in new_idmap_permitted()
847 if (ns_capable(ns->parent, cap_setid) && in new_idmap_permitted()
848 file_ns_capable(file, ns->parent, cap_setid)) in new_idmap_permitted()
856 struct user_namespace *ns = seq->private; in proc_setgroups_show() local
857 unsigned long userns_flags = ACCESS_ONCE(ns->flags); in proc_setgroups_show()
869 struct user_namespace *ns = seq->private; in proc_setgroups_write() local
910 if (!(ns->flags & USERNS_SETGROUPS_ALLOWED)) in proc_setgroups_write()
916 if (ns->gid_map.nr_extents != 0) in proc_setgroups_write()
918 ns->flags &= ~USERNS_SETGROUPS_ALLOWED; in proc_setgroups_write()
932 bool userns_may_setgroups(const struct user_namespace *ns) in userns_may_setgroups() argument
940 allowed = ns->gid_map.nr_extents != 0; in userns_may_setgroups()
942 allowed = allowed && (ns->flags & USERNS_SETGROUPS_ALLOWED); in userns_may_setgroups()
948 static inline struct user_namespace *to_user_ns(struct ns_common *ns) in to_user_ns() argument
950 return container_of(ns, struct user_namespace, ns); in to_user_ns()
961 return user_ns ? &user_ns->ns : NULL; in userns_get()
964 static void userns_put(struct ns_common *ns) in userns_put() argument
966 put_user_ns(to_user_ns(ns)); in userns_put()
969 static int userns_install(struct nsproxy *nsproxy, struct ns_common *ns) in userns_install() argument
971 struct user_namespace *user_ns = to_user_ns(ns); in userns_install()