Skip to content
  • Eric W. Biederman's avatar
    userns: Allow the userns root to mount tmpfs. · 2b8576cb
    Eric W. Biederman authored
    
    
    There is no backing store to tmpfs and file creation rules are the
    same as for any other filesystem so it is semantically safe to allow
    unprivileged users to mount it.  ramfs is safe for the same reasons so
    allow either flavor of tmpfs to be mounted by a user namespace root
    user.
    
    The memory control group successfully limits how much memory tmpfs can
    consume on any system that cares about a user namespace root using
    tmpfs to exhaust memory the memory control group can be deployed.
    
    Signed-off-by: default avatar"Eric W. Biederman" <ebiederm@xmission.com>
    2b8576cb