On Sun, Apr 12, 2020 at 10:25:33PM +0200, Eugene Syromiatnikov wrote: > Checking that cgroup field value of struct clone_args is less than 0 > is useless, as it is defined as unsigned 64-bit integer. Moreover, > it doesn't catch the situations where its higher bits are lost during > the assignment to the cgroup field of the cgroup field of the internal > struct kernel_clone_args (where it is declared as signed 32-bit > integer), so it is still possible to pass garbage there. A check > against INT_MAX solves both these issues. > > Fixes: ef2c41cf38a7559b ("clone3: allow spawning processes into cgroups") > Signed-off-by: Eugene Syromiatnikov <esyr@xxxxxxxxxx> > Acked-by: Christian Brauner <christian.brauner@xxxxxxxxxx> Applied, thanks! Christian