mbox series

[v2,0/5] ovl: metacopy/verity fixes and improvements

Message ID 20250325104634.162496-1-mszeredi@redhat.com (mailing list archive)
Headers show
Series ovl: metacopy/verity fixes and improvements | expand

Message

Miklos Szeredi March 25, 2025, 10:46 a.m. UTC
The main purpose of this patchset is allowing metadata/data-only layers to
be usable in user namespaces (without super user privs).

v2:
	- drop broken hunk in param.c (Amir)
	- patch header improvements (Amir)

---
Giuseppe Scrivano (1):
  ovl: remove unused forward declaration

Miklos Szeredi (4):
  ovl: don't allow datadir only
  ovl: make redirect/metacopy rejection consistent
  ovl: relax redirect/metacopy requirements for lower -> data redirect
  ovl: don't require "metacopy=on" for "verity"

 Documentation/filesystems/overlayfs.rst |  7 +++
 fs/overlayfs/namei.c                    | 77 ++++++++++++++++---------
 fs/overlayfs/overlayfs.h                |  2 -
 fs/overlayfs/params.c                   | 16 +----
 fs/overlayfs/super.c                    |  5 ++
 5 files changed, 66 insertions(+), 41 deletions(-)

Comments

Amir Goldstein March 25, 2025, 12:04 p.m. UTC | #1
On Tue, Mar 25, 2025 at 11:46 AM Miklos Szeredi <mszeredi@redhat.com> wrote:
>
> The main purpose of this patchset is allowing metadata/data-only layers to
> be usable in user namespaces (without super user privs).

Please add test coverage to this use case.
I think a userxattr variant of test overlay/080 should be easy.

Thanks,
Amir.