From: Daniel Lezcano <dlezcano@fr.ibm.com>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, benjamin.thery@bull.net
Subject: [patch net-2.6.25 08/10][NETNS][IPV6] make mld_max_msf readonly in other namespaces
Date: Wed, 09 Jan 2008 17:45:41 +0100 [thread overview]
Message-ID: <20080109165034.129870447@localhost.localdomain> (raw)
In-Reply-To: 20080109164533.695191040@localhost.localdomain
[-- Attachment #1: make-mld_max_msf-readonly.patch --]
[-- Type: text/plain, Size: 1366 bytes --]
The mld_max_msf protects the system with a maximum allowed multicast
source filters. Making this variable per namespace can be potentially
an problem if someone inside a namespace set it to a big value, that
will impact the whole system including other namespaces.
I don't see any benefits to have it per namespace for now, so in order
to keep a directory entry in a newly created namespace, I make it
read-only when we are not in the initial network namespace.
Signed-off-by: Daniel Lezcano <dlezcano@fr.ibm.com>
---
net/ipv6/sysctl_net_ipv6.c | 6 ++++++
1 file changed, 6 insertions(+)
Index: net-2.6.25/net/ipv6/sysctl_net_ipv6.c
===================================================================
--- net-2.6.25.orig/net/ipv6/sysctl_net_ipv6.c
+++ net-2.6.25/net/ipv6/sysctl_net_ipv6.c
@@ -122,6 +122,12 @@ static int ipv6_sysctl_net_init(struct n
ipv6_table[5].data = &net->ipv6.sysctl.frags.timeout;
ipv6_table[6].data = &net->ipv6.sysctl.frags.secret_interval;
+ /* We don't want this value to be per namespace, it should be global
+ to all namespaces, so make it read-only when we are not in the
+ init network namespace */
+ if (net != &init_net)
+ ipv6_table[7].mode = 0444;
+
net->ipv6.sysctl.table = register_net_sysctl_table(net, net_ipv6_ctl_path,
ipv6_table);
if (!net->ipv6.sysctl.table)
--
next prev parent reply other threads:[~2008-01-09 17:00 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-01-09 16:45 [patch net-2.6.25 00/10][NETNS][IPV6] make sysctl per namespace - V3 Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 01/10][NETNS][IPV6] make ipv6_sysctl_register to return a value Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 02/10][NETNS][IPV6] make a subsystem for af_inet6 Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 03/10][NETNS][IPV6] add ipv6 structure for netns Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 04/10][NETNS][IPV6] make the ipv6 sysctl to be a netns subsystem Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 05/10][NETNS][IPV6] make multiple instance of sysctl tables Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 06/10][NETNS][IPV6] make bindv6only sysctl per namespace Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 07/10][NETNS][IPV6] make ip6_frags " Daniel Lezcano
2008-01-09 16:45 ` Daniel Lezcano [this message]
2008-01-09 16:45 ` [patch net-2.6.25 09/10][NETNS][IPV6] make sysctls route " Daniel Lezcano
2008-01-09 16:45 ` [patch net-2.6.25 10/10][NETNS][IPV6] make icmpv6_time sysctl " Daniel Lezcano
2008-01-10 11:15 ` [patch net-2.6.25 00/10][NETNS][IPV6] make sysctl per namespace - V3 David Miller
2008-01-10 11:52 ` Daniel Lezcano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080109165034.129870447@localhost.localdomain \
--to=dlezcano@fr.ibm.com \
--cc=benjamin.thery@bull.net \
--cc=davem@davemloft.net \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.