netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: David Miller <davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
To: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org
Cc: netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
	containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org
Subject: Re: [REVIEW][PATCH 0/21] User namespace changes to the networking stack.
Date: Fri, 24 Aug 2012 21:42:37 -0400 (EDT)	[thread overview]
Message-ID: <20120824.214237.2157641321364380276.davem@davemloft.net> (raw)
In-Reply-To: <87boicfyo9.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>

From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
Date: Tue, 14 Aug 2012 23:37:42 -0700

> David Miller <davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org> writes:
> 
>> From: ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org (Eric W. Biederman)
>> Date: Mon, 13 Aug 2012 13:07:10 -0700
>>
>>> 
>>> This is a modest set of changes against the current networking stack to
>>> enable basic user namespace support.  Allowing the code to compile with
>>> user namespaces enabled and removing the assumption that there is only
>>> the initial user namespace.
>>> 
>>> Work to relax the privilege checks in the networking stack from
>>> "capable(CAP_NET_ADMIN)" or "capable(CAP_NET_RAW)" to
>>> "ns_capable(net->user_ns, CAP_NET_ADMIN)" or 
>>> "ns_capable(net->user_ns, CAP_NET_RAW)" allowing root in a user
>>> namespace to control a network namespace will come later.
>>> 
>>> David there are just enough interdependencies between the user namespace
>>> bits that I intend to merge them all through my user namespace tree.
>>> After the review is complete I will add these patches to my for-next
>>> branch of my user-namespace.git tree where I do not intend to rebase.
>>> If it make sense to pull these into net-next to avoid or reduce
>>> conflicts that should not be a problem.
>>
>> Looks fine to me, you can add:
>>
>> Acked-by: David S. Miller <davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
>>
>> to all of this stuff.  Let me know when something is stable in your
>> tree, and I can therefore pull from it into net-next.
> 
> All of these patches + 2 others trivial userns bug fixes are now
> in my for-next branch at:
> 
> git.kernel.org:/pub/scm/linux/kernel/git/ebiederm/user-namespace.git for-next

Ok I finally got around to pushing this into net-next, thanks.

  parent reply	other threads:[~2012-08-25  1:42 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-08-13 20:07 [REVIEW][PATCH 0/21] User namespace changes to the networking stack Eric W. Biederman
     [not found] ` <87ehnav9n5.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:18   ` [PATCH 01/21] userns: Convert net/core/scm.c to use kuids and kgids Eric W. Biederman
2012-08-13 20:18     ` [PATCH 10/21] userns: Convert net/ax25 to use kuid_t where appropriate Eric W. Biederman
     [not found]     ` <1344889115-21610-1-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:18       ` [PATCH 02/21] userns: Convert __dev_set_promiscuity to use kuids in audit logs Eric W. Biederman
2012-08-13 20:18       ` [PATCH 03/21] userns: Convert sock_i_uid to return a kuid_t Eric W. Biederman
2012-08-13 20:18       ` [PATCH 04/21] userns: Allow USER_NS and NET simultaneously in Kconfig Eric W. Biederman
2012-08-13 20:18       ` [PATCH 05/21] userns: Make seq_file's user namespace accessible Eric W. Biederman
2012-08-13 20:18       ` [PATCH 06/21] userns: Print out socket uids in a user namespace aware fashion Eric W. Biederman
     [not found]         ` <1344889115-21610-6-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-13 20:26           ` Rémi Denis-Courmont
     [not found]             ` <201208132326.35045.remi-AzDNUFsAnHasTnJN9+BGXg@public.gmane.org>
2012-08-15  4:47               ` Eric W. Biederman
2012-08-15  3:22           ` Vlad Yasevich
2012-08-13 20:18       ` [PATCH 07/21] userns: Use kgids for sysctl_ping_group_range Eric W. Biederman
     [not found]         ` <1344889115-21610-7-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-20 18:09           ` Vasiliy Kulikov
2012-08-13 20:18       ` [PATCH 08/21] net ip6 flowlabel: Make owner a union of struct pid * and kuid_t Eric W. Biederman
2012-08-13 20:18       ` [PATCH 09/21] pidns: Export free_pid_ns Eric W. Biederman
2012-08-13 20:18       ` [PATCH 11/21] netlink: Make the sending netlink socket availabe in NETLINK_CB Eric W. Biederman
2012-08-13 20:18       ` [PATCH 12/21] userns: Implement sk_user_ns Eric W. Biederman
2012-08-13 20:18       ` [PATCH 13/21] userns: Teach inet_diag to work with user namespaces Eric W. Biederman
     [not found]         ` <1344889115-21610-13-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-14  8:35           ` Pavel Emelyanov
2012-08-13 20:18       ` [PATCH 14/21] userns: nfnetlink_log: Report socket uids in the log sockets user namespace Eric W. Biederman
2012-08-13 20:18       ` [PATCH 15/21] net sched: Pass the skb into change so it can access NETLINK_CB Eric W. Biederman
     [not found]         ` <1344889115-21610-15-git-send-email-ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-15  8:11           ` Jamal Hadi Salim
2012-08-13 20:18       ` [PATCH 16/21] userns: Convert cls_flow to work with user namespaces enabled Eric W. Biederman
2012-08-13 20:18       ` [PATCH 17/21] userns: Convert xt_LOG to print socket kuids and kgids as uids and gids Eric W. Biederman
2012-08-13 20:18       ` [PATCH 18/21] userns xt_recent: Specify the owner/group of ip_list_perms in the initial user namespace Eric W. Biederman
2012-08-13 20:18       ` [PATCH 19/21] userns: xt_owner: Add basic user namespace support Eric W. Biederman
2012-08-13 20:18       ` [PATCH 20/21] userns: Make the airo wireless driver use kuids for proc uids and gids Eric W. Biederman
2012-08-13 20:18       ` [PATCH 21/21] userns: Convert tun/tap to use kuid and kgid where appropriate Eric W. Biederman
2012-08-15  0:12   ` [REVIEW][PATCH 0/21] User namespace changes to the networking stack David Miller
2012-08-15  0:47     ` Eric W. Biederman
     [not found]     ` <20120814.171203.1784557890475348401.davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
2012-08-15  6:37       ` Eric W. Biederman
     [not found]         ` <87boicfyo9.fsf-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org>
2012-08-25  1:42           ` David Miller [this message]
     [not found]             ` <20120824.214237.2157641321364380276.davem-fT/PcQaiUtIeIZ0/mPfg9Q@public.gmane.org>
2012-08-25  3:46               ` Eric W. Biederman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20120824.214237.2157641321364380276.davem@davemloft.net \
    --to=davem-ft/pcqaiutieiz0/mpfg9q@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=ebiederm-aS9lmoZGLiVWk0Htik3J/w@public.gmane.org \
    --cc=netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).