Thread (1 message) 1 message, 1 author, 2012-08-15

Re: [REVIEW][PATCH 0/21] User namespace changes to the networking stack.

From: Eric W. Biederman <hidden>
Date: 2012-08-15 06:37:42

David Miller [off-list ref] writes:
From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
Date: Mon, 13 Aug 2012 13:07:10 -0700
quoted
This is a modest set of changes against the current networking stack to
enable basic user namespace support.  Allowing the code to compile with
user namespaces enabled and removing the assumption that there is only
the initial user namespace.

Work to relax the privilege checks in the networking stack from
"capable(CAP_NET_ADMIN)" or "capable(CAP_NET_RAW)" to
"ns_capable(net->user_ns, CAP_NET_ADMIN)" or 
"ns_capable(net->user_ns, CAP_NET_RAW)" allowing root in a user
namespace to control a network namespace will come later.

David there are just enough interdependencies between the user namespace
bits that I intend to merge them all through my user namespace tree.
After the review is complete I will add these patches to my for-next
branch of my user-namespace.git tree where I do not intend to rebase.
If it make sense to pull these into net-next to avoid or reduce
conflicts that should not be a problem.
Looks fine to me, you can add:

Acked-by: David S. Miller <davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>

to all of this stuff.  Let me know when something is stable in your
tree, and I can therefore pull from it into net-next.
All of these patches + 2 others trivial userns bug fixes are now
in my for-next branch at:

git.kernel.org:/pub/scm/linux/kernel/git/ebiederm/user-namespace.git for-next

I won't be rebasing that branch so feel free to merge it into net-next
if you are so inclined.  It will be a day or two before I get my next
chunk of patches posted, reviewed and ready to join my for-next branch.

Eric
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help