aboutsummaryrefslogtreecommitdiff
path: root/hw/display/ati_2d.c
diff options
context:
space:
mode:
authorStefan Hajnoczi <stefanha@redhat.com>2019-03-12 15:51:38 +0000
committerDr. David Alan Gilbert <dgilbert@redhat.com>2020-01-23 16:41:36 +0000
commit5baa3b8e95064c2434bd9e2f312edd5e9ae275dc (patch)
tree4ee8509f3cbef95d26b0aea4c8d3131f8b28a09b /hw/display/ati_2d.c
parent9f59d175e2ca96f0b87f534dba69ea547dd35945 (diff)
virtiofsd: sandbox mount namespace
Use a mount namespace with the shared directory tree mounted at "/" and no other mounts. This prevents symlink escape attacks because symlink targets are resolved only against the shared directory and cannot go outside it. Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com> Signed-off-by: Peng Tao <tao.peng@linux.alibaba.com> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Signed-off-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Diffstat (limited to 'hw/display/ati_2d.c')
0 files changed, 0 insertions, 0 deletions