* [PATCH] Fix recommended permissions for /dev/net/tun
@ 2006-06-20 15:35 David Woodhouse
2006-06-20 16:18 ` David Woodhouse
2006-06-20 19:36 ` [PATCH] Require CAP_NET_ADMIN to create tuntap devices David Woodhouse
0 siblings, 2 replies; 5+ messages in thread
From: David Woodhouse @ 2006-06-20 15:35 UTC (permalink / raw)
To: netdev
There's no reason to restrict unprivileged users from opening
the /dev/net/tun device node -- to do anything exciting requires
CAP_NET_ADMIN or a persistent device which is owned by the user in
question anyway. And if it _isn't_ openable by unprivileged users, then
giving ownership of devices to those users is a fairly pointless
exercise.
Signed-Off-By: David Woodhouse <dwmw2@infradead.org>
diff --git a/Documentation/networking/tuntap.txt b/Documentation/networking/tuntap.txt
index 76750fb..9d696f2 100644
--- a/Documentation/networking/tuntap.txt
+++ b/Documentation/networking/tuntap.txt
@@ -39,10 +39,13 @@ Copyright (C) 1999-2000 Maxim Krasnyansk
mknod /dev/net/tun c 10 200
Set permissions:
- e.g. chmod 0700 /dev/net/tun
- if you want the device only accessible by root. Giving regular users the
- right to assign network devices is NOT a good idea. Users could assign
- bogus network interfaces to trick firewalls or administrators.
+ e.g. chmod 0666 /dev/net/tun
+ There's no harm in allowing the device to be accessible by non-root users,
+ since CAP_NET_ADMIN is required for creating network devices or for
+ connecting to network devices which aren't owned by the user in question.
+ If you want to create persistent devices and give ownership of them to
+ unprivileged users, then you need the /dev/net/tun device to be usable by
+ those users.
Driver module autoloading
--
dwmw2
^ permalink raw reply related [flat|nested] 5+ messages in thread* Re: [PATCH] Fix recommended permissions for /dev/net/tun
2006-06-20 15:35 [PATCH] Fix recommended permissions for /dev/net/tun David Woodhouse
@ 2006-06-20 16:18 ` David Woodhouse
2006-06-20 16:46 ` Chase Venters
2006-06-20 19:36 ` [PATCH] Require CAP_NET_ADMIN to create tuntap devices David Woodhouse
1 sibling, 1 reply; 5+ messages in thread
From: David Woodhouse @ 2006-06-20 16:18 UTC (permalink / raw)
To: netdev
On Tue, 2006-06-20 at 16:35 +0100, David Woodhouse wrote:
> There's no reason to restrict unprivileged users from opening
> the /dev/net/tun device node -- to do anything exciting requires
> CAP_NET_ADMIN or a persistent device which is owned by the user in
> question anyway.
Hm, I lie. Let us alter reality to match my previous perception of it...
[PATCH] Require CAP_SYS_ADMIN to create tuntap devices.
The tuntap driver allows an admin to create persistent devices and
assign ownership of them to individual users. Unfortunately, relaxing
the permissions on the /dev/net/tun device node _also_ allows those
users to create arbitrary new devices of their own. This patch corrects
that, and adjusts the recommended permissions for the device node
accordingly.
Signed-Off-By: David Woodhouse <dwmw2@infradead.org>
diff --git a/Documentation/networking/tuntap.txt b/Documentation/networking/tuntap.txt
index 76750fb..839cbb7 100644
--- a/Documentation/networking/tuntap.txt
+++ b/Documentation/networking/tuntap.txt
@@ -39,10 +39,13 @@ Copyright (C) 1999-2000 Maxim Krasnyansk
mknod /dev/net/tun c 10 200
Set permissions:
- e.g. chmod 0700 /dev/net/tun
- if you want the device only accessible by root. Giving regular users the
- right to assign network devices is NOT a good idea. Users could assign
- bogus network interfaces to trick firewalls or administrators.
+ e.g. chmod 0666 /dev/net/tun
+ There's no harm in allowing the device to be accessible by non-root users,
+ since CAP_NET_ADMIN is required for creating network devices or for
+ connecting to network devices which aren't owned by the user in question.
+ If you want to create persistent devices and give ownership of them to
+ unprivileged users, then you need the /dev/net/tun device to be usable by
+ those users.
Driver module autoloading
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index a1ed2d9..6c62d5c 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -490,6 +490,9 @@ static int tun_set_iff(struct file *file
err = -EINVAL;
+ if (!capable(CAP_NET_ADMIN))
+ return -EPERM;
+
/* Set dev type */
if (ifr->ifr_flags & IFF_TUN) {
/* TUN device */
--
dwmw2
^ permalink raw reply related [flat|nested] 5+ messages in thread* Re: [PATCH] Fix recommended permissions for /dev/net/tun
2006-06-20 16:18 ` David Woodhouse
@ 2006-06-20 16:46 ` Chase Venters
2006-06-20 17:04 ` David Woodhouse
0 siblings, 1 reply; 5+ messages in thread
From: Chase Venters @ 2006-06-20 16:46 UTC (permalink / raw)
To: David Woodhouse; +Cc: netdev
On Tue, 20 Jun 2006, David Woodhouse wrote:
> On Tue, 2006-06-20 at 16:35 +0100, David Woodhouse wrote:
>> There's no reason to restrict unprivileged users from opening
>> the /dev/net/tun device node -- to do anything exciting requires
>> CAP_NET_ADMIN or a persistent device which is owned by the user in
>> question anyway.
>
> Hm, I lie. Let us alter reality to match my previous perception of it...
Perhaps you lie again :)
Are you sure you're adding a capable(CAP_SYS_ADMIN)? :P
> [PATCH] Require CAP_SYS_ADMIN to create tuntap devices.
>
> The tuntap driver allows an admin to create persistent devices and
> assign ownership of them to individual users. Unfortunately, relaxing
> the permissions on the /dev/net/tun device node _also_ allows those
> users to create arbitrary new devices of their own. This patch corrects
> that, and adjusts the recommended permissions for the device node
> accordingly.
>
> Signed-Off-By: David Woodhouse <dwmw2@infradead.org>
>
> diff --git a/Documentation/networking/tuntap.txt b/Documentation/networking/tuntap.txt
> index 76750fb..839cbb7 100644
> --- a/Documentation/networking/tuntap.txt
> +++ b/Documentation/networking/tuntap.txt
> @@ -39,10 +39,13 @@ Copyright (C) 1999-2000 Maxim Krasnyansk
> mknod /dev/net/tun c 10 200
>
> Set permissions:
> - e.g. chmod 0700 /dev/net/tun
> - if you want the device only accessible by root. Giving regular users the
> - right to assign network devices is NOT a good idea. Users could assign
> - bogus network interfaces to trick firewalls or administrators.
> + e.g. chmod 0666 /dev/net/tun
> + There's no harm in allowing the device to be accessible by non-root users,
> + since CAP_NET_ADMIN is required for creating network devices or for
> + connecting to network devices which aren't owned by the user in question.
> + If you want to create persistent devices and give ownership of them to
> + unprivileged users, then you need the /dev/net/tun device to be usable by
> + those users.
>
> Driver module autoloading
>
> diff --git a/drivers/net/tun.c b/drivers/net/tun.c
> index a1ed2d9..6c62d5c 100644
> --- a/drivers/net/tun.c
> +++ b/drivers/net/tun.c
> @@ -490,6 +490,9 @@ static int tun_set_iff(struct file *file
>
> err = -EINVAL;
>
> + if (!capable(CAP_NET_ADMIN))
> + return -EPERM;
> +
> /* Set dev type */
> if (ifr->ifr_flags & IFF_TUN) {
> /* TUN device */
>
>
>
Thanks,
Chase
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH] Require CAP_NET_ADMIN to create tuntap devices.
2006-06-20 15:35 [PATCH] Fix recommended permissions for /dev/net/tun David Woodhouse
2006-06-20 16:18 ` David Woodhouse
@ 2006-06-20 19:36 ` David Woodhouse
1 sibling, 0 replies; 5+ messages in thread
From: David Woodhouse @ 2006-06-20 19:36 UTC (permalink / raw)
To: netdev
The tuntap driver allows an admin to create persistent devices and
assign ownership of them to individual users. Unfortunately, relaxing
the permissions on the /dev/net/tun device node so that they can
actually use those devices will _also_ allow those users to create
arbitrary new devices of their own. This patch corrects that, and
adjusts the recommended permissions for the device node accordingly.
Signed-Off-By: David Woodhouse <dwmw2@infradead.org>
diff --git a/Documentation/networking/tuntap.txt b/Documentation/networking/tuntap.txt
index 76750fb..839cbb7 100644
--- a/Documentation/networking/tuntap.txt
+++ b/Documentation/networking/tuntap.txt
@@ -39,10 +39,13 @@ Copyright (C) 1999-2000 Maxim Krasnyansk
mknod /dev/net/tun c 10 200
Set permissions:
- e.g. chmod 0700 /dev/net/tun
- if you want the device only accessible by root. Giving regular users the
- right to assign network devices is NOT a good idea. Users could assign
- bogus network interfaces to trick firewalls or administrators.
+ e.g. chmod 0666 /dev/net/tun
+ There's no harm in allowing the device to be accessible by non-root users,
+ since CAP_NET_ADMIN is required for creating network devices or for
+ connecting to network devices which aren't owned by the user in question.
+ If you want to create persistent devices and give ownership of them to
+ unprivileged users, then you need the /dev/net/tun device to be usable by
+ those users.
Driver module autoloading
diff --git a/drivers/net/tun.c b/drivers/net/tun.c
index a1ed2d9..6c62d5c 100644
--- a/drivers/net/tun.c
+++ b/drivers/net/tun.c
@@ -490,6 +490,9 @@ static int tun_set_iff(struct file *file
err = -EINVAL;
+ if (!capable(CAP_NET_ADMIN))
+ return -EPERM;
+
/* Set dev type */
if (ifr->ifr_flags & IFF_TUN) {
/* TUN device */
--
dwmw2
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2006-06-20 19:36 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-20 15:35 [PATCH] Fix recommended permissions for /dev/net/tun David Woodhouse
2006-06-20 16:18 ` David Woodhouse
2006-06-20 16:46 ` Chase Venters
2006-06-20 17:04 ` David Woodhouse
2006-06-20 19:36 ` [PATCH] Require CAP_NET_ADMIN to create tuntap devices David Woodhouse
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox