On Tue, Feb 07, 2017 at 07:59:00PM +0200, Amir Goldstein wrote: > I am not even sure that would be enough. > dentry does not contain information about the mount user came from, > and sb contains only information about the user ns of the mounter of > the file system, not the mounter of the bind mount, right? > I think I am missing some big pieces of the big picture. > Would love to hear what Eric has to say. IFF we want to do what shiftfs does properly we need vfsmount + inode, no need for the dentry. But maybe we need to go back and decice if we want to allow uid/gid remapping for arbitrary subtrees anyway. Another option would be to require something like a project as used for project quotas as the root. This would also be conveniant as it could storge the used remapping tables.