A remount request must (a) not convert a union to a non-union (or vice versa), or (b) make the topmost layer of a union read-only. Note that we only have to worry about attempts to remount the vfsmount of the topmost read-write of the union (the one with MNT_UNION set). The vfsmounts of the read-only layers are hidden in a cloned tree hanging of the superblock of the topmost layer and aren't visible to userspace. Signed-off-by: Valerie Aurora <vaurora@xxxxxxxxxx> --- fs/namespace.c | 12 ++++++++++++ 1 files changed, 12 insertions(+), 0 deletions(-) diff --git a/fs/namespace.c b/fs/namespace.c index ff83cee..61256e6 100644 --- a/fs/namespace.c +++ b/fs/namespace.c @@ -1824,6 +1824,18 @@ static int do_remount(struct path *path, int flags, int mnt_flags, if (!check_mnt(path->mnt)) return -EINVAL; + if ((path->mnt->mnt_flags & MNT_UNION) && + !(mnt_flags & MNT_UNION)) + return -EINVAL; + + if ((mnt_flags & MNT_UNION) && + !(path->mnt->mnt_flags & MNT_UNION)) + return -EINVAL; + + if ((path->mnt->mnt_flags & MNT_UNION) && + (mnt_flags & MNT_READONLY)) + return -EINVAL; + if (path->dentry != path->mnt->mnt_root) return -EINVAL; -- 1.6.3.3 -- To unsubscribe from this list: send the line "unsubscribe linux-fsdevel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html