UBUNTU: SAUCE: Yama: verify inode is symlink to avoid bind mounts
The inode_follow_link LSM hook is called in bind mount situations as
well as for symlink situations, so we must explicitly check for the
inode being a symlink to not reject bind mounts in 1777 directories,
which seems to be a common NFSv4 configuration.
BugLink: https://bugs.launchpad.net/bugs/604407
[submitted upstream to security-next]
Signed-off-by: Kees Cook <kees.cook@canonical.com>
Signed-off-by: Leann Ogasawara <leann.ogasawara@canonical.com>