From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933473AbcECNIn (ORCPT ); Tue, 3 May 2016 09:08:43 -0400 Received: from mail-pa0-f42.google.com ([209.85.220.42]:35264 "EHLO mail-pa0-f42.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932903AbcECNIm convert rfc822-to-8bit (ORCPT ); Tue, 3 May 2016 09:08:42 -0400 Content-Type: text/plain; charset=gb2312 Mime-Version: 1.0 (Mac OS X Mail 9.2 \(3112\)) Subject: Re: [Question] Should `CAP_NET_ADMIN` be needed when opening `/dev/ppp`? From: =?gb2312?B?zfXl4w==?= In-Reply-To: <1462274614.1336993.596603129.675ECADD@webmail.messagingengine.com> Date: Tue, 3 May 2016 21:08:45 +0800 Cc: Richard Weinberger , Guillaume Nault , netdev@vger.kernel.org, LKML Content-Transfer-Encoding: 8BIT Message-Id: <04054B5D-AD85-47ED-8666-21C7399BC121@gmail.com> References: <2BEB0C68-EBC6-4A8F-A751-DE8F4A2C9D2C@gmail.com> <20160503101240.GA1304@alphalink.fr> <1462274614.1336993.596603129.675ECADD@webmail.messagingengine.com> To: Hannes Frederic Sowa X-Mailer: Apple Mail (2.3112) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org > 在 2016年5月3日,下午7:23,Hannes Frederic Sowa 写道: > > On Tue, May 3, 2016, at 12:35, Richard Weinberger wrote: >> On Tue, May 3, 2016 at 12:12 PM, Guillaume Nault >> wrote: >>> On Sun, May 01, 2016 at 09:38:57PM +0800, Wang Shanker wrote: >>>> static int ppp_open(struct inode *inode, struct file *file) >>>> { >>>> /* >>>> * This could (should?) be enforced by the permissions on /dev/ppp. >>>> */ >>>> if (!capable(CAP_NET_ADMIN)) >>>> return -EPERM; >>>> return 0; >>>> } >>>> ``` >>>> >>>> I wonder why CAP_NET_ADMIN is needed here, rather than leaving it to the >>>> permission of the device node. If there is no need, I suggest that the >>>> CAP_NET_ADMIN check be removed. >>>> >>> If this test was removed here, then it'd have to be added again in the >>> PPPIOCNEWUNIT ioctl, at the very least, because creating a netdevice >>> should require CAP_NET_ADMIN. Therefore that wouldn't help for your >>> case. >>> I don't know why the test was placed in ppp_open() in the first place, >>> but changing it now would have side effects on user space. So I'd >>> rather leave the code as is. >> >> I think the question is whether we really require having CAP_NET_ADMIN >> in the initial namespace and not just in the current one. >> Is ppp not network namespace aware? > > I agree, ns_capable(net->user_ns, CAP_NET_ADMIN), would probably make > more sense. I agree with that. > > Bye, > Hannes