netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* IPv6 extension header privileges
@ 2016-05-20 22:37 Tom Herbert
  2016-05-21  0:20 ` Hannes Frederic Sowa
  2016-05-27  3:37 ` YOSHIFUJI Hideaki
  0 siblings, 2 replies; 24+ messages in thread
From: Tom Herbert @ 2016-05-20 22:37 UTC (permalink / raw)
  To: Linux Kernel Network Developers, Hideaki YOSHIFUJI

Hi,

In ipv6_sockglue.c I noticed:

/* hop-by-hop / destination options are privileged option */
retv = -EPERM;
if (optname != IPV6_RTHDR && !ns_capable(net->user_ns, CAP_NET_RAW))
           break;

Can anyone provide that rationale as to why these are privileged ops?

Thanks,
Tom

^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2016-05-27 17:38 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-05-20 22:37 IPv6 extension header privileges Tom Herbert
2016-05-21  0:20 ` Hannes Frederic Sowa
2016-05-21  1:56   ` Sowmini Varadhan
2016-05-21  9:34     ` Hannes Frederic Sowa
2016-05-21 10:02       ` Sowmini Varadhan
2016-05-21 15:19       ` Tom Herbert
2016-05-21 15:33         ` Hannes Frederic Sowa
2016-05-21 16:00           ` Tom Herbert
2016-05-21 16:16             ` Hannes Frederic Sowa
2016-05-21 17:46               ` Sowmini Varadhan
2016-05-22  1:08                 ` Hannes Frederic Sowa
2016-05-22 11:56                   ` Sowmini Varadhan
2016-05-22 12:13                     ` Hannes Frederic Sowa
2016-05-23 18:11                     ` Tom Herbert
2016-05-26 18:42                       ` Tom Herbert
2016-05-27  9:53                         ` Hannes Frederic Sowa
2016-05-27 15:03                           ` Sowmini Varadhan
2016-05-27 16:59                             ` Tom Herbert
2016-05-27 17:14                               ` Hannes Frederic Sowa
2016-05-27 17:38                                 ` Tom Herbert
2016-05-27 16:46                         ` Hannes Frederic Sowa
2016-05-27 17:05                           ` Tom Herbert
2016-05-21 16:28             ` Hannes Frederic Sowa
2016-05-27  3:37 ` YOSHIFUJI Hideaki

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).