[$] Mounting images inside a user namespace

Post Syndicated from original https://lwn.net/Articles/934176/

There has long been a desire to enable users to mount filesystem images without
requiring privileges, but the security
implications of allowing it are seriously concerning. Few, if any, kernel
filesystems are hardened against maliciously crafted images, after all.
Lennart Poettering led a filesystem session at the
2023 Linux Storage, Filesystem,
Memory-Management and BPF Summit
where he presented a possible path
forward.