google / google/gvisor

Check for user namespaces in FUSE filesystems with `allow_other`

Open
#12,663 1 comment 0 reactions 0 assignees View on GitHub
stale-issue type: bug
Dominant language
Go
Stars
19.3k
Forks
2k
Avg merge
3d 5h
Merged PRs (30d)
264

Description

### Description

The file access check for FUSE filesystems mounted with the `allow_other` mount option should take user namespaces into account.

### Steps to reproduce

_No response_

### runsc version

```shell

```

### docker version (if using docker)

```shell

```

### uname

_No response_

### kubectl (if using Kubernetes)

```shell

```

### repo state (if built from source)

_No response_

### runsc debug logs (if available)

```shell

```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.