Skip to content

The time namespace's stated limit names every source of the machine's clock a zone reads - #321

Open
DevomB wants to merge 2 commits into
mainfrom
time-namespace-limit
Open

DevomB wants to merge 2 commits into
mainfrom
time-namespace-limit

Conversation

@DevomB

@DevomB DevomB commented Oct 9, 2026

Copy link
Copy Markdown
Owner

What was wrong

The threat model's "Still shown" list and the net zone surface note gave two ways for a zone to get past its own clocks: the offsets in /proc/self/timens_offsets, and the scheduler's clock in /proc/<pid>/sched. Two more sources were not named, and neither can be withheld from a zone:

  • The vDSO's time data. In Linux 6.18 a task in a time namespace gets the page with its offsets mapped in its vDSO data area, and the machine's own time data mapped in the next page, both readable. The vDSO reads both to answer clock_gettime (lib/vdso/datastore.c, vvar_fault).
  • The CPU's timestamp counter. Any program reads it with rdtsc in user space, and it counts on from the CPU's reset whatever namespace reads it.

What changed

Docs only:

  • docs/threat-model.md: the "Still shown" list names all four sources as giving the machine's uptime to code that looks past the zone's own clocks.
  • docs/design/net-zone-surface.md: the time namespace section and the "leaves" row of the side-by-side table name all four sources.

The time namespace still keeps the shared uptime and boot time out of what crash reports and telemetry send. What it does not do is unchanged: it does not stop a zone that is trying to link itself to another.

How the run proves it

Docs only, so CI. The kernel references are checked against v6.18:

  • lib/vdso/datastore.c maps the real time data at the time-namespace page offset when the task has a time-namespace page.
  • fs/proc/base.c:3330 registers sched with no debug guard.

DevomB added 2 commits October 9, 2026 13:04
… clock a zone reads

The threat model and the net zone surface note named two ways past a zone's
own clocks: the offsets in /proc/self/timens_offsets and the scheduler's clock
in /proc/<pid>/sched. A zone also reads the machine's time data straight from
the vDSO, whose next page a time namespace maps readable beside the page of
its offsets (lib/vdso/datastore.c, vvar_fault), and the CPU's timestamp
counter, which rdtsc reads in user space. Both now say so, as sources code
that looks for them reads the machine's uptime from.
@DevomB
DevomB marked this pull request as ready for review October 9, 2026 20:12

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant