From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 52B3E3C1D76 for ; Sun, 9 Aug 2026 09:42:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.175 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786268580; cv=none; b=plVD80+t94IjmMx3Ax4FHE4qtKlwQZmScKLpsutkQwaxSFRHOp8uvbfsyci48au+o/xumtLTi9d9rpUerxoSE8JvGeLTRqIXQ1yOG9E8PtX99dAXiSRxaVzZQekyz1yvFzEb2z21pE3BdUtuBllnr99w7jw+28CZ35BErW7JvUE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786268580; c=relaxed/simple; bh=YFtlLngdvCDKxznwW0KFwwqo5LsMIr5V1JdUsdpWzWk=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=NlwYCsaGC8fsa3ldc7EEqu7Wm7AAUV0P0ZEhW4W4rJ1/zkTMKQTDkc0GJ+j+nWf3nOzxcMSDn4i4AMVFq/LHSXiIsi3vm4YeJknYaANrp8Az0R3hihZmWTf9nRnH/fRPNFkzWyFPrU0GfdHbmVtDgA1lMc8aITIWBOy2RcnNU6M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pb18o9tR; arc=none smtp.client-ip=209.85.215.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pb18o9tR" Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-c9e7391839cso899370a12.0 for ; Sun, 09 Aug 2026 02:42:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786268579; x=1786873379; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5vhVP2gwsOdEitAqeBQ2V+u61oT/f5wQ296ftm0EiMs=; b=pb18o9tRybnkrPGAam/bPg6Z/2VTapgxIxyPUN+VKxNzFvlAAmzp0RtYNwFqajuL+b AMJ3cI1ruaWkw5gYMYJGMLGeGG38EBbNMnHQvMe0wnjrBRhlTOVPTbtzVAs2PQh70lR1 s7DoXqbGannCnObLjsS9b/JySF0kkEjWrFIl+pGA+f0McenqTquGWs6PRWFchvP1xm1K jTYPKjYEWCcoGJy5UxmWfAqsIjvq8LJZtngQIPncTAp3s5OMaSIQLU1/zZ8DO23YtJ1o n2gv0G58YHUNwmW3VRZTlWo99kjSVsgJhg2RO+D9W1HljiReYU5jR7FdckpdrQbABaF/ JyOw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786268579; x=1786873379; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5vhVP2gwsOdEitAqeBQ2V+u61oT/f5wQ296ftm0EiMs=; b=fl1rzQxt6V5i4LgqMng/GqhHxhGz+lIXMPuhTazG7E8vDSinmb+fOeQqkS3n3UAD+J j6UdV/BDNbCX2ooBHjWEoRbGwgT0ekxwDw017NVtYQ0PDkCuiH9e7QmGwz0vVWSA99KX DDFVPFtyoW9eAzE/E8jVteNL/t4CnajY/pRVsIC6E5UlJxPHLN9FlgJOUBqpigMTdOan L7S9PP98xpHcvDwaRWDJqYhvgq7CJBDPkfT0nSSIA1tsCDG0wqZFGSxTRl+ZDHY6Gtfy 3Itq4BcRBuJ2AnFe48WD8zrE6Y2qIBJi2ikfmFHdPlO0HE5SHO7Eej/DvhCDtx+b1wXz PUQA== X-Forwarded-Encrypted: i=1; AHgh+RrLr+ZiJ+IQtYsYm9MTCCWzZE3QW6Tk6hS97+qVN4cADDLK617CN51GAzcqhUM1w4xkLZizpi/3rBKWMXg=@vger.kernel.org X-Gm-Message-State: AOJu0YwBCS3d3MZMT/2i9rOsKaZ/R3jGDyOSDfhQe7D0pqdH+IIbsJzJ NeTaD795tfgS+JPEvbx5U97JdTlBO9RxkCc09fHIZGJJCKVjMTMKnwHm X-Gm-Gg: AR+sD11nkRu4kqUijvOdeG+te8/iXeJN0xUkKxHUyGfIjaXf/4Nc2BpfnMo4CaxxoSx So8MGbW4IQ0ZVd7MxNGoAztQd6hZxsQb0onk4uLyCYx/AmlvuJIjIDBZjgkUtSjCdAgutB1HfnD +rmdZilnG8QCAoBX5QRUo2zah/ZCuLFs9xzT31xoiBQkSBt6PwgHPYuT/KXUG4ktoh/VuwOvuCY GWJo7vPOeq5wk882MwyoVSfFthNvIoSOyzD8wSaQVSz/ZfT/z5N77fE6llhLEOlfG/+1kmFynWg mBODbfbETlGHD31chUzG9Ew+wGV36U8ikIU99v6eevC2m8oHNOhweOiWO7MjXI8Dq1nyp3p1d6A 5CBiwNfzUl6Xf3QEO1m8HkrWt4QjZFLJ5OVgF24oz/L34pm/Lj+1zRcFJSuOwXWkxopwv+Ufxm2 IUpHZpNi5f5AWLSBp8kjxO/faqLSw0YmbyJQAG+CkBh925TSp8QBVBeUeki+0Nszi/9NQnhzgTF qOfPbg2YqYt2w== X-Received: by 2002:a05:6a21:6f17:b0:3c3:724d:ae7a with SMTP id adf61e73a8af0-3cbc0175426mr21235402637.9.1786268578350; Sun, 09 Aug 2026 02:42:58 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be8d60f4sm29364303eec.13.2026.08.09.02.42.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 02:42:57 -0700 (PDT) From: Maoyi Xie To: "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: James Chapman , Tom Parkin , Guillaume Nault , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net] l2tp: send netlink notifications in the tunnel's net namespace Date: Sun, 9 Aug 2026 17:42:52 +0800 Message-Id: <20260809094252.2107242-1-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit l2tp_tunnel_notify() and l2tp_session_notify() use genlmsg_multicast_allns(), which delivers to listeners in every network namespace. l2tp is per-namespace, and a tunnel records the namespace it belongs to in tunnel->l2tp_net. Each event concerns one namespace, yet every namespace is told about it. A tunnel event carries the tunnel and peer tunnel ids, plus the socket's addresses with both ports for a UDP tunnel. A session event carries the session and peer session ids, the interface name, plus the L2TP cookies where those are set. A listener needs no privilege for any of this, because l2tp_multicast_group[] carries no flags and genl_bind() asks for no capability. The fix is to send to the tunnel's namespace with genlmsg_multicast_netns(). Commit 134e63756d5f ("genetlink: make netns aware") added both helpers and drew the line between them. The netns variant is for an object that lives in a namespace. I found this by auditing the tree's six genlmsg_multicast_allns() call sites for objects that live in a network namespace. Only the two l2tp ones do. I reproduced it on net at dd057113ac7b, in a virtual machine, with no real hardware involved. A process in the initial namespace, running as an ordinary user with an empty capability set, receives the create and delete events of a tunnel. The tunnel was set up inside an unprivileged user and network namespace. tools/testing/selftests/net/l2tp.sh passes before and after. On a container host, any local user and every other tenant can read a tenant's tunnel parameters. Fixes: 33f72e6f0c67 ("l2tp : multicast notification to the registered listeners") Cc: stable@vger.kernel.org Signed-off-by: Maoyi Xie --- net/l2tp/l2tp_netlink.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/net/l2tp/l2tp_netlink.c b/net/l2tp/l2tp_netlink.c index 59457c0c14aab..c0c4d1ebc7a3e 100644 --- a/net/l2tp/l2tp_netlink.c +++ b/net/l2tp/l2tp_netlink.c @@ -116,7 +116,8 @@ static int l2tp_tunnel_notify(struct genl_family *family, NLM_F_ACK, tunnel, cmd); if (ret >= 0) { - ret = genlmsg_multicast_allns(family, msg, 0, 0); + ret = genlmsg_multicast_netns(family, tunnel->l2tp_net, msg, + 0, 0, GFP_KERNEL); /* We don't care if no one is listening */ if (ret == -ESRCH) ret = 0; @@ -144,7 +145,9 @@ static int l2tp_session_notify(struct genl_family *family, NLM_F_ACK, session, cmd); if (ret >= 0) { - ret = genlmsg_multicast_allns(family, msg, 0, 0); + ret = genlmsg_multicast_netns(family, + session->tunnel->l2tp_net, msg, + 0, 0, GFP_KERNEL); /* We don't care if no one is listening */ if (ret == -ESRCH) ret = 0;