On Thu, Apr 28, 2022 at 01:35:32PM +0200, Miklos Szeredi wrote: > On Thu, 28 Apr 2022 at 13:30, Miklos Szeredi <miklos@xxxxxxxxxx> wrote: > > > So I guess the proper fix would be to introduce a version of > > lookup_one_len() without inode_permission()... > > OTOH, we do have CAP_DAC_READ_SEARCH already in the syscall path and > knfsd won't be using mnt_userns, so just passing init_user_ns should > be fine as a quick fix. > > I'm in the process of applying these patches, so if there's no > objection, I'll make this change. Sounds good! Thank your for fixing this up in-tree. Appreciate it!