Comment 10 for bug 1402834

Revision history for this message
Seth Forshee (sforshee) wrote :

I didn't see the irc discussion. Atm we don't have a concept of a owner or "master" namespace for a super block, though I expect we will see it in the future. And I agree it doesn't seem to make sense to let a less privileged userns to do this to a more privileged namespace. However if we ignore MNT_FORCE if there are mounts in any other namespace this would allow a lesser privileged namespace to block MNT_FORCE for a more privileged one, which is also undesirable.