]> git.baikalelectronics.ru Git - kernel.git/commit
Merge branch 'net-openvswitch-metering-and-conntrack-in-userns'
authorPaolo Abeni <pabeni@redhat.com>
Tue, 27 Sep 2022 09:31:54 +0000 (11:31 +0200)
committerPaolo Abeni <pabeni@redhat.com>
Tue, 27 Sep 2022 09:31:54 +0000 (11:31 +0200)
commita3bbed3f8d049c547f863dca91641ba9724e388d
tree30e1132a7877b5b0ba315cdfb4c16f5edc54ecf0
parent6fcd4aecd56bceb86e1817835cd9fd48754f3904
parentcc2de08de50a0cef5e17fff55b216347a69dcd64
Merge branch 'net-openvswitch-metering-and-conntrack-in-userns'

Michael Weiß says:

====================
net: openvswitch: metering and conntrack in userns

Currently using openvswitch in a non-initial user namespace, e.g., an
unprivileged container, is possible but without metering and conntrack
support. This is due to the restriction of the corresponding Netlink
interfaces to the global CAP_NET_ADMIN.

This simple patches switch from GENL_ADMIN_PERM to GENL_UNS_ADMIN_PERM
in several cases to allow this also for the unprivileged container
use case.

We tested this for unprivileged containers created by the container
manager of GyroidOS (gyroidos.github.io). However, for other container
managers such as LXC or systemd which provide unprivileged containers
this should be apply equally.
====================

Link: https://lore.kernel.org/r/20220923133820.993725-1-michael.weiss@aisec.fraunhofer.de
Signed-off-by: Paolo Abeni <pabeni@redhat.com>