mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
net: devmem: allow bind-rx from non-init user namespaces
NETDEV_CMD_BIND_RX is currently GENL_ADMIN_PERM, which checks CAP_NET_ADMIN against init userns. With recent container/netkit/ns support for devmem, other userns/netns use cases come online and require bind-rx to allow CAP_NET_ADMIN in non-init user ns as well. Switch the flag to GENL_UNS_ADMIN_PERM to allow bind-rx for CAP_NET_ADMIN in the netns's owning userns as well. Signed-off-by: Bobby Eshleman <bobbyeshleman@meta.com> Acked-by: Stanislav Fomichev <sdf@fomichev.me> Link: https://patch.msgid.link/20260602-nl-prov-v2-1-ad721142c641@meta.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
9410fb4da2
commit
e302aa3d00
@@ -798,7 +798,7 @@ operations:
|
||||
name: bind-rx
|
||||
doc: Bind dmabuf to netdev
|
||||
attribute-set: dmabuf
|
||||
flags: [admin-perm]
|
||||
flags: [uns-admin-perm]
|
||||
do:
|
||||
request:
|
||||
attributes:
|
||||
|
||||
@@ -220,7 +220,7 @@ static const struct genl_split_ops netdev_nl_ops[] = {
|
||||
.doit = netdev_nl_bind_rx_doit,
|
||||
.policy = netdev_bind_rx_nl_policy,
|
||||
.maxattr = NETDEV_A_DMABUF_FD,
|
||||
.flags = GENL_ADMIN_PERM | GENL_CMD_CAP_DO,
|
||||
.flags = GENL_UNS_ADMIN_PERM | GENL_CMD_CAP_DO,
|
||||
},
|
||||
{
|
||||
.cmd = NETDEV_CMD_NAPI_SET,
|
||||
|
||||
Reference in New Issue
Block a user