]> git.baikalelectronics.ru Git - kernel.git/commit
Merge branch 'net-openvswitch-metering-and-conntrack-in-userns'
authorPaolo Abeni <pabeni@redhat.com>
Tue, 27 Sep 2022 09:31:54 +0000 (11:31 +0200)
committerPaolo Abeni <pabeni@redhat.com>
Tue, 27 Sep 2022 09:31:54 +0000 (11:31 +0200)
commitf9170cf35984999cb6188ca40d4905bb9fa24dd2
tree30e1132a7877b5b0ba315cdfb4c16f5edc54ecf0
parent042c8571cd919c397d48f0fa9be91e64ec64d9a3
parent487bbe7b2973e2f8fe5559064321b22490d61c03
Merge branch 'net-openvswitch-metering-and-conntrack-in-userns'

Michael Weiß says:

====================
net: openvswitch: metering and conntrack in userns

Currently using openvswitch in a non-initial user namespace, e.g., an
unprivileged container, is possible but without metering and conntrack
support. This is due to the restriction of the corresponding Netlink
interfaces to the global CAP_NET_ADMIN.

This simple patches switch from GENL_ADMIN_PERM to GENL_UNS_ADMIN_PERM
in several cases to allow this also for the unprivileged container
use case.

We tested this for unprivileged containers created by the container
manager of GyroidOS (gyroidos.github.io). However, for other container
managers such as LXC or systemd which provide unprivileged containers
this should be apply equally.
====================

Link: https://lore.kernel.org/r/20220923133820.993725-1-michael.weiss@aisec.fraunhofer.de
Signed-off-by: Paolo Abeni <pabeni@redhat.com>