mirror of
https://mirrors.bfsu.edu.cn/git/linux.git
synced 2024-11-26 05:34:13 +08:00
[NET]: Disable netfilter sockopts when not in the initial network namespace
Until we support multiple network namespaces with netfilter only allow netfilter configuration in the initial network namespace. Signed-off-by: Eric W. Biederman <ebiederm@xmission.com> Signed-off-by: David S. Miller <davem@davemloft.net>
This commit is contained in:
parent
d8a5ec6727
commit
c48dad7ecd
@ -69,6 +69,9 @@ static int nf_sockopt(struct sock *sk, int pf, int val,
|
|||||||
struct nf_sockopt_ops *ops;
|
struct nf_sockopt_ops *ops;
|
||||||
int ret;
|
int ret;
|
||||||
|
|
||||||
|
if (sk->sk_net != &init_net)
|
||||||
|
return -ENOPROTOOPT;
|
||||||
|
|
||||||
if (mutex_lock_interruptible(&nf_sockopt_mutex) != 0)
|
if (mutex_lock_interruptible(&nf_sockopt_mutex) != 0)
|
||||||
return -EINTR;
|
return -EINTR;
|
||||||
|
|
||||||
@ -125,6 +128,10 @@ static int compat_nf_sockopt(struct sock *sk, int pf, int val,
|
|||||||
struct nf_sockopt_ops *ops;
|
struct nf_sockopt_ops *ops;
|
||||||
int ret;
|
int ret;
|
||||||
|
|
||||||
|
if (sk->sk_net != &init_net)
|
||||||
|
return -ENOPROTOOPT;
|
||||||
|
|
||||||
|
|
||||||
if (mutex_lock_interruptible(&nf_sockopt_mutex) != 0)
|
if (mutex_lock_interruptible(&nf_sockopt_mutex) != 0)
|
||||||
return -EINTR;
|
return -EINTR;
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user