For quite a while we have been thinking about using pidfds to attach to namespaces. This patchset has existed for about a year already but we've wanted to wait to see how the general api would be received and adopted. Now that more and more programs in userspace have started using pidfds for process management it's time to send this one out. This patch makes it possible to use pidfds to attach to the namespaces of another process, i.e. they can be passed as the first argument to the setns() syscall. When only a single namespace type is specified the semantics are equivalent to passing an nsfd. That means setns(nsfd, CLONE_NEWNET) equals setns(pidfd, CLONE_NEWNET). However, when a pidfd is passed, multiple namespace flags can be specified in the second setns() argument and setns() will attach the caller to all the specified namespaces all at once or to none of them. Specifying 0 is not valid together with a pidfd. Here are just two obvious examples: setns(pidfd, CLONE_NEWPID | CLONE_NEWNS | CLONE_NEWNET); setns(pidfd, CLONE_NEWUSER); Allowing to also attach subsets of namespaces supports various use-cases where callers setns to a subset of namespaces to retain privilege, perform an action and then re-attach another subset of namespaces. If the need arises, as Eric suggested, we can extend this patchset to assume even more context than just attaching all namespaces. His suggestion specifically was about assuming the process' root directory when setns(pidfd, 0) or setns(pidfd, SETNS_PIDFD) is specified. For now, just keep it flexible in terms of supporting subsets of namespaces but let's wait until we have users asking for even more context to be assumed. At that point we can add an extension. The obvious example where this is useful is a standard container manager interacting with a running container: pushing and pulling files or directories, injecting mounts, attaching/execing any kind of process, managing network devices all these operations require attaching to all or at least multiple namespaces at the same time. Given that nowadays most containers are spawned with all namespaces enabled we're currently looking at at least 14 syscalls, 7 to open the /proc/<pid>/ns/<ns> nsfds, another 7 to actually perform the namespace switch. With time namespaces we're looking at about 16 syscalls. (We could amortize the first 7 or 8 syscalls for opening the nsfds by stashing them in each container's monitor process but that would mean we need to send around those file descriptors through unix sockets everytime we want to interact with the container or keep on-disk state. Even in scenarios where a caller wants to join a particular namespace in a particular order callers still profit from batching other namespaces. That mostly applies to the user namespace but all container runtimes I found join the user namespace first no matter if it privileges or deprivileges the container similar to how unshare behaves.) With pidfds this becomes a single syscall no matter how many namespaces are supposed to be attached to. A decently designed, large-scale container manager usually isn't the parent of any of the containers it spawns so the containers don't die when it crashes or needs to update or reinitialize. This means that for the manager to interact with containers through pids is inherently racy especially on systems where the maximum pid number is not significicantly bumped. This is even more problematic since we often spawn and manage thousands or ten-thousands of containers. Interacting with a container through a pid thus can become risky quite quickly. Especially since we allow for an administrator to enable advanced features such as syscall interception where we're performing syscalls in lieu of the container. In all of those cases we use pidfds if they are available and we pass them around as stable references. Using them to setns() to the target process' namespaces is as reliable as using nsfds. Either the target process is already dead and we get ESRCH or we manage to attach to its namespaces but we can't accidently attach to another process' namespaces. So pidfds lend themselves to be used with this api. The other main advantage is that with this change the pidfd becomes the only relevant token for most container interactions and it's the only token we need to create and send around. Apart from significiantly reducing the number of syscalls from double digit to single digit which is a decent reason post-spectre/meltdown this also allows to switch to a set of namespaces atomically, i.e. either attaching to all the specified namespaces succeeds or we fail. If we fail we haven't changed a single namespace. There are currently three namespaces that can fail (other than for ENOMEM which really is not very interesting since we then have other problems anyway) for non-trivial reasons, user, mount, and pid namespaces. We can fail to attach to a pid namespace if it is not our current active pid namespace or a descendant of it. We can fail to attach to a user namespace because we are multi-threaded or because our current mount namespace shares filesystem state with other tasks, or because we're trying to setns() to the same user namespace, i.e. the target task has the same user namespace as we do. We can fail to attach to a mount namespace because it shares filesystem state with other tasks or because we fail to lookup the new root for the new mount namespace. In most non-pathological scenarios these issues can be somewhat mitigated. But there are cases where we're half-attached to some namespace and failing to attach to another one. I've talked about some of these problem during the hallway track (something only the pre-COVID-19 generation will remember) of Plumbers in Los Angeles in 2018(?). Even if all these issues could be avoided with super careful userspace coding it would be nicer to have this done in-kernel. Pidfds seem to lend themselves nicely for this. The other neat thing about this is that setns() becomes an actual counterpart to the namespace bits of unshare(). Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com> Reviewed-by: Serge Hallyn <serge@hallyn.com> Cc: Eric W. Biederman <ebiederm@xmission.com> Cc: Serge Hallyn <serge@hallyn.com> Cc: Jann Horn <jannh@google.com> Cc: Michael Kerrisk <mtk.manpages@gmail.com> Cc: Aleksa Sarai <cyphar@cyphar.com> Link: https://lore.kernel.org/r/20200505140432.181565-3-christian.brauner@ubuntu.com
		
			
				
	
	
		
			307 lines
		
	
	
		
			6.6 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			307 lines
		
	
	
		
			6.6 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
| // SPDX-License-Identifier: GPL-2.0
 | |
| #include <linux/mount.h>
 | |
| #include <linux/pseudo_fs.h>
 | |
| #include <linux/file.h>
 | |
| #include <linux/fs.h>
 | |
| #include <linux/proc_fs.h>
 | |
| #include <linux/proc_ns.h>
 | |
| #include <linux/magic.h>
 | |
| #include <linux/ktime.h>
 | |
| #include <linux/seq_file.h>
 | |
| #include <linux/user_namespace.h>
 | |
| #include <linux/nsfs.h>
 | |
| #include <linux/uaccess.h>
 | |
| 
 | |
| #include "internal.h"
 | |
| 
 | |
| static struct vfsmount *nsfs_mnt;
 | |
| 
 | |
| static long ns_ioctl(struct file *filp, unsigned int ioctl,
 | |
| 			unsigned long arg);
 | |
| static const struct file_operations ns_file_operations = {
 | |
| 	.llseek		= no_llseek,
 | |
| 	.unlocked_ioctl = ns_ioctl,
 | |
| };
 | |
| 
 | |
| static char *ns_dname(struct dentry *dentry, char *buffer, int buflen)
 | |
| {
 | |
| 	struct inode *inode = d_inode(dentry);
 | |
| 	const struct proc_ns_operations *ns_ops = dentry->d_fsdata;
 | |
| 
 | |
| 	return dynamic_dname(dentry, buffer, buflen, "%s:[%lu]",
 | |
| 		ns_ops->name, inode->i_ino);
 | |
| }
 | |
| 
 | |
| static void ns_prune_dentry(struct dentry *dentry)
 | |
| {
 | |
| 	struct inode *inode = d_inode(dentry);
 | |
| 	if (inode) {
 | |
| 		struct ns_common *ns = inode->i_private;
 | |
| 		atomic_long_set(&ns->stashed, 0);
 | |
| 	}
 | |
| }
 | |
| 
 | |
| const struct dentry_operations ns_dentry_operations =
 | |
| {
 | |
| 	.d_prune	= ns_prune_dentry,
 | |
| 	.d_delete	= always_delete_dentry,
 | |
| 	.d_dname	= ns_dname,
 | |
| };
 | |
| 
 | |
| static void nsfs_evict(struct inode *inode)
 | |
| {
 | |
| 	struct ns_common *ns = inode->i_private;
 | |
| 	clear_inode(inode);
 | |
| 	ns->ops->put(ns);
 | |
| }
 | |
| 
 | |
| static int __ns_get_path(struct path *path, struct ns_common *ns)
 | |
| {
 | |
| 	struct vfsmount *mnt = nsfs_mnt;
 | |
| 	struct dentry *dentry;
 | |
| 	struct inode *inode;
 | |
| 	unsigned long d;
 | |
| 
 | |
| 	rcu_read_lock();
 | |
| 	d = atomic_long_read(&ns->stashed);
 | |
| 	if (!d)
 | |
| 		goto slow;
 | |
| 	dentry = (struct dentry *)d;
 | |
| 	if (!lockref_get_not_dead(&dentry->d_lockref))
 | |
| 		goto slow;
 | |
| 	rcu_read_unlock();
 | |
| 	ns->ops->put(ns);
 | |
| got_it:
 | |
| 	path->mnt = mntget(mnt);
 | |
| 	path->dentry = dentry;
 | |
| 	return 0;
 | |
| slow:
 | |
| 	rcu_read_unlock();
 | |
| 	inode = new_inode_pseudo(mnt->mnt_sb);
 | |
| 	if (!inode) {
 | |
| 		ns->ops->put(ns);
 | |
| 		return -ENOMEM;
 | |
| 	}
 | |
| 	inode->i_ino = ns->inum;
 | |
| 	inode->i_mtime = inode->i_atime = inode->i_ctime = current_time(inode);
 | |
| 	inode->i_flags |= S_IMMUTABLE;
 | |
| 	inode->i_mode = S_IFREG | S_IRUGO;
 | |
| 	inode->i_fop = &ns_file_operations;
 | |
| 	inode->i_private = ns;
 | |
| 
 | |
| 	dentry = d_alloc_anon(mnt->mnt_sb);
 | |
| 	if (!dentry) {
 | |
| 		iput(inode);
 | |
| 		return -ENOMEM;
 | |
| 	}
 | |
| 	d_instantiate(dentry, inode);
 | |
| 	dentry->d_fsdata = (void *)ns->ops;
 | |
| 	d = atomic_long_cmpxchg(&ns->stashed, 0, (unsigned long)dentry);
 | |
| 	if (d) {
 | |
| 		d_delete(dentry);	/* make sure ->d_prune() does nothing */
 | |
| 		dput(dentry);
 | |
| 		cpu_relax();
 | |
| 		return -EAGAIN;
 | |
| 	}
 | |
| 	goto got_it;
 | |
| }
 | |
| 
 | |
| int ns_get_path_cb(struct path *path, ns_get_path_helper_t *ns_get_cb,
 | |
| 		     void *private_data)
 | |
| {
 | |
| 	int ret;
 | |
| 
 | |
| 	do {
 | |
| 		struct ns_common *ns = ns_get_cb(private_data);
 | |
| 		if (!ns)
 | |
| 			return -ENOENT;
 | |
| 		ret = __ns_get_path(path, ns);
 | |
| 	} while (ret == -EAGAIN);
 | |
| 
 | |
| 	return ret;
 | |
| }
 | |
| 
 | |
| struct ns_get_path_task_args {
 | |
| 	const struct proc_ns_operations *ns_ops;
 | |
| 	struct task_struct *task;
 | |
| };
 | |
| 
 | |
| static struct ns_common *ns_get_path_task(void *private_data)
 | |
| {
 | |
| 	struct ns_get_path_task_args *args = private_data;
 | |
| 
 | |
| 	return args->ns_ops->get(args->task);
 | |
| }
 | |
| 
 | |
| int ns_get_path(struct path *path, struct task_struct *task,
 | |
| 		  const struct proc_ns_operations *ns_ops)
 | |
| {
 | |
| 	struct ns_get_path_task_args args = {
 | |
| 		.ns_ops	= ns_ops,
 | |
| 		.task	= task,
 | |
| 	};
 | |
| 
 | |
| 	return ns_get_path_cb(path, ns_get_path_task, &args);
 | |
| }
 | |
| 
 | |
| int open_related_ns(struct ns_common *ns,
 | |
| 		   struct ns_common *(*get_ns)(struct ns_common *ns))
 | |
| {
 | |
| 	struct path path = {};
 | |
| 	struct file *f;
 | |
| 	int err;
 | |
| 	int fd;
 | |
| 
 | |
| 	fd = get_unused_fd_flags(O_CLOEXEC);
 | |
| 	if (fd < 0)
 | |
| 		return fd;
 | |
| 
 | |
| 	do {
 | |
| 		struct ns_common *relative;
 | |
| 
 | |
| 		relative = get_ns(ns);
 | |
| 		if (IS_ERR(relative)) {
 | |
| 			put_unused_fd(fd);
 | |
| 			return PTR_ERR(relative);
 | |
| 		}
 | |
| 
 | |
| 		err = __ns_get_path(&path, relative);
 | |
| 	} while (err == -EAGAIN);
 | |
| 
 | |
| 	if (err) {
 | |
| 		put_unused_fd(fd);
 | |
| 		return err;
 | |
| 	}
 | |
| 
 | |
| 	f = dentry_open(&path, O_RDONLY, current_cred());
 | |
| 	path_put(&path);
 | |
| 	if (IS_ERR(f)) {
 | |
| 		put_unused_fd(fd);
 | |
| 		fd = PTR_ERR(f);
 | |
| 	} else
 | |
| 		fd_install(fd, f);
 | |
| 
 | |
| 	return fd;
 | |
| }
 | |
| EXPORT_SYMBOL_GPL(open_related_ns);
 | |
| 
 | |
| static long ns_ioctl(struct file *filp, unsigned int ioctl,
 | |
| 			unsigned long arg)
 | |
| {
 | |
| 	struct user_namespace *user_ns;
 | |
| 	struct ns_common *ns = get_proc_ns(file_inode(filp));
 | |
| 	uid_t __user *argp;
 | |
| 	uid_t uid;
 | |
| 
 | |
| 	switch (ioctl) {
 | |
| 	case NS_GET_USERNS:
 | |
| 		return open_related_ns(ns, ns_get_owner);
 | |
| 	case NS_GET_PARENT:
 | |
| 		if (!ns->ops->get_parent)
 | |
| 			return -EINVAL;
 | |
| 		return open_related_ns(ns, ns->ops->get_parent);
 | |
| 	case NS_GET_NSTYPE:
 | |
| 		return ns->ops->type;
 | |
| 	case NS_GET_OWNER_UID:
 | |
| 		if (ns->ops->type != CLONE_NEWUSER)
 | |
| 			return -EINVAL;
 | |
| 		user_ns = container_of(ns, struct user_namespace, ns);
 | |
| 		argp = (uid_t __user *) arg;
 | |
| 		uid = from_kuid_munged(current_user_ns(), user_ns->owner);
 | |
| 		return put_user(uid, argp);
 | |
| 	default:
 | |
| 		return -ENOTTY;
 | |
| 	}
 | |
| }
 | |
| 
 | |
| int ns_get_name(char *buf, size_t size, struct task_struct *task,
 | |
| 			const struct proc_ns_operations *ns_ops)
 | |
| {
 | |
| 	struct ns_common *ns;
 | |
| 	int res = -ENOENT;
 | |
| 	const char *name;
 | |
| 	ns = ns_ops->get(task);
 | |
| 	if (ns) {
 | |
| 		name = ns_ops->real_ns_name ? : ns_ops->name;
 | |
| 		res = snprintf(buf, size, "%s:[%u]", name, ns->inum);
 | |
| 		ns_ops->put(ns);
 | |
| 	}
 | |
| 	return res;
 | |
| }
 | |
| 
 | |
| bool proc_ns_file(const struct file *file)
 | |
| {
 | |
| 	return file->f_op == &ns_file_operations;
 | |
| }
 | |
| 
 | |
| struct file *proc_ns_fget(int fd)
 | |
| {
 | |
| 	struct file *file;
 | |
| 
 | |
| 	file = fget(fd);
 | |
| 	if (!file)
 | |
| 		return ERR_PTR(-EBADF);
 | |
| 
 | |
| 	if (file->f_op != &ns_file_operations)
 | |
| 		goto out_invalid;
 | |
| 
 | |
| 	return file;
 | |
| 
 | |
| out_invalid:
 | |
| 	fput(file);
 | |
| 	return ERR_PTR(-EINVAL);
 | |
| }
 | |
| 
 | |
| /**
 | |
|  * ns_match() - Returns true if current namespace matches dev/ino provided.
 | |
|  * @ns_common: current ns
 | |
|  * @dev: dev_t from nsfs that will be matched against current nsfs
 | |
|  * @ino: ino_t from nsfs that will be matched against current nsfs
 | |
|  *
 | |
|  * Return: true if dev and ino matches the current nsfs.
 | |
|  */
 | |
| bool ns_match(const struct ns_common *ns, dev_t dev, ino_t ino)
 | |
| {
 | |
| 	return (ns->inum == ino) && (nsfs_mnt->mnt_sb->s_dev == dev);
 | |
| }
 | |
| 
 | |
| 
 | |
| static int nsfs_show_path(struct seq_file *seq, struct dentry *dentry)
 | |
| {
 | |
| 	struct inode *inode = d_inode(dentry);
 | |
| 	const struct proc_ns_operations *ns_ops = dentry->d_fsdata;
 | |
| 
 | |
| 	seq_printf(seq, "%s:[%lu]", ns_ops->name, inode->i_ino);
 | |
| 	return 0;
 | |
| }
 | |
| 
 | |
| static const struct super_operations nsfs_ops = {
 | |
| 	.statfs = simple_statfs,
 | |
| 	.evict_inode = nsfs_evict,
 | |
| 	.show_path = nsfs_show_path,
 | |
| };
 | |
| 
 | |
| static int nsfs_init_fs_context(struct fs_context *fc)
 | |
| {
 | |
| 	struct pseudo_fs_context *ctx = init_pseudo(fc, NSFS_MAGIC);
 | |
| 	if (!ctx)
 | |
| 		return -ENOMEM;
 | |
| 	ctx->ops = &nsfs_ops;
 | |
| 	ctx->dops = &ns_dentry_operations;
 | |
| 	return 0;
 | |
| }
 | |
| 
 | |
| static struct file_system_type nsfs = {
 | |
| 	.name = "nsfs",
 | |
| 	.init_fs_context = nsfs_init_fs_context,
 | |
| 	.kill_sb = kill_anon_super,
 | |
| };
 | |
| 
 | |
| void __init nsfs_init(void)
 | |
| {
 | |
| 	nsfs_mnt = kern_mount(&nsfs);
 | |
| 	if (IS_ERR(nsfs_mnt))
 | |
| 		panic("can't set nsfs up\n");
 | |
| 	nsfs_mnt->mnt_sb->s_flags &= ~SB_NOUSER;
 | |
| }
 |