From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86C2C2FCBFC for ; Thu, 12 Feb 2026 20:59:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770929969; cv=none; b=fuZfI5i6S86Q3NpJ6agl6iWNG3L1lZCWHk4xX0aWIoGDY4zFlLsfGQ41rJhgjk/l24NI//lgQ1zqkk/53NW2hZLDojY+V/g1O0EUuHZoCnmTwaDzQGEDzF5VVNASwQLk9MdtfL5SFGEtYTVZ5HHJEnGD3CPQaWLQACmsvEUhFpg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770929969; c=relaxed/simple; bh=GfXVbSIiCSvAfNsvXZFkw5pPzo6pnCYgQ7VhFaW9av4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JAxSGkADW/DvAE+rgwuUP/zmNUbqbs4qpglzZytwLvPAEKKzp//+zymqBFkMH6fUNmwIJq0tGfcKhJhg36RJgLlYC5yCRiLLpOPw3dBw58tbKtLmvN5Pafisd/DQQtQLfSYrES9ZpXScyYqQERZ1UzlzWoAb3oD/YNPtYGqLkXE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=eBN3OgNQ; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=Az2hU/wp; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="eBN3OgNQ"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="Az2hU/wp" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1770929967; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1qRvoym6nLJZOIFftihpZCiMWAoHUET6JGe7MHQ2xs4=; b=eBN3OgNQ0TzuHJNu4Qkcx+id3TNZ4BnYIy+l15xD8atLCDgHOW3kmoYNHSIMHwMKK5itXP BvXVTPVoUjNekTDzxWmVneJAg2hayBMeXL93gwEEIgaZTYcHwtNXkpIedDkbGr/kxr5ojE s40PSanUzZhaITwTqrRJ2QfSCzN7pow= Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-287-8Nzq8_ahNfCW7UlSwl0f9A-1; Thu, 12 Feb 2026 15:59:25 -0500 X-MC-Unique: 8Nzq8_ahNfCW7UlSwl0f9A-1 X-Mimecast-MFC-AGG-ID: 8Nzq8_ahNfCW7UlSwl0f9A_1770929964 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-43637c70876so159641f8f.2 for ; Thu, 12 Feb 2026 12:59:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1770929964; x=1771534764; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=1qRvoym6nLJZOIFftihpZCiMWAoHUET6JGe7MHQ2xs4=; b=Az2hU/wpRDbv8sNYPDDkqR1bO3SAsUoAdD3h0n9HVTDFuSP+KGgclcavoPKQJGwY3T mlMHmkNXY2LjImus5i02wujNFS3zE2nC52MKMP6QfZBhVxomPhnzluJguj6+1sARo55C kOezZfmUhfh5figB3fi5K/Bu2uovtTw1Dg5zBXcpm6Rhks/spPiYT/keEpB+PRuAV0IG M2NSkdj3s0oQcP860ExRek3U1OrmKgulPvA1i5BS7eY4rFgBl1NxdXZFaBY4cNLzQ+56 Hueez8WygkOoqgMNgHWAijrXw3nBsW7M0YN31yWaquG2GDpUKrSS/SWY6k9fJ5LoCC3v +/ug== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770929964; x=1771534764; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=1qRvoym6nLJZOIFftihpZCiMWAoHUET6JGe7MHQ2xs4=; b=Lc4pmifpDKtcckHMYiARKRUrHl/NvHsk+lizApXf+1jeyCpRr9vfSdRaUAJoA6k92R TGSWl+hzDdUoy8Z1l8FhISzZFAEeBGad1e6pDh+W5iUBefkmdD0/H8ksGw4y9VYE4ght ukxsL3N3vNFUE0ZvJ0DMj/UB4UdUs24OtOGIl99nzzmgar+NL8qXnSVvBj6Vu/r9muS4 8rZJjQ5JaAiD5mJMVOvqE8Kdtibel/mVkK8Zmn3JLjyTnxrZ8e4U39cSxSOevBVG5mrQ 8JcQDRYdNo9A/PtulZEE+5mvB7Lv8ACiDy5ViGZoFcy+5al1Xer3YNpFf32rNup/gsnj eS9Q== X-Forwarded-Encrypted: i=1; AJvYcCXaAO9fk2uh9OdVA7t6ESukExIAZJIzOaDqJU3QTtbDkliqT0khOBumn+tFBPczyZBorD2deOIi0nZ0guI=@vger.kernel.org X-Gm-Message-State: AOJu0YzYqA9h7Q2t0UCyOxbBtJvjnU2qlMVEN2mzV0qC9ontlB1fI0MW gjoquIbrZInapQU/PZngKxgugPrnV4X4JyhYNVc9wd1pPYX5Qn3jnq5xE71jffViOJKgPFus/d5 RaXbH4shoz6GIEQpv73LcX1iQ6X7Xes33EGBMd4Q1idZfXp4VJEmfxKQNLs1UOvSBhA== X-Gm-Gg: AZuq6aJO29rkJwK0bItfZzwv2F15zX8qpKzywTJfewcC2jXR8cR0M8u1YHkh97hURfg d7SDJXu0qcz5gT+taXIOzWzgYfevsLx/tA8wdSovd0b8a+S3iDdw3AY+qR0RGtfEzJUxrMGIIEF W1WCTbPHEBiQExR43q/ifBdMwxxmIgs4f6m9Egc1c39XeFhLsDxhfzWyDk8NSYqHsWpOMsai0Nf T/XzdR89mBHAdfHbfdILx58z2oIJEB5lxVdrFguFIjqOq7ArO9aqlf/Jd0YAgllJKm8kRoMis4H U29FNt6+HPYw8NqGbIUADX9UjhxuY/x2grePFEGalL1S9xI5X9h3BZZoRCPu2zb6ZJFsVj9NUr+ ZSJx5aXoDpoKaOWhJlj/UTKc3DGWGRyPg9IojCC+Pe8HBbnjYsRKHETeZPg== X-Received: by 2002:a05:6000:2003:b0:435:8aa1:ff4d with SMTP id ffacd0b85a97d-43796aa67c4mr421860f8f.22.1770929963771; Thu, 12 Feb 2026 12:59:23 -0800 (PST) X-Received: by 2002:a05:6000:2003:b0:435:8aa1:ff4d with SMTP id ffacd0b85a97d-43796aa67c4mr421834f8f.22.1770929963268; Thu, 12 Feb 2026 12:59:23 -0800 (PST) Received: from stex1 (host-82-53-134-58.retail.telecomitalia.it. [82.53.134.58]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43796abd793sm465791f8f.25.2026.02.12.12.59.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 12 Feb 2026 12:59:22 -0800 (PST) From: Stefano Garzarella To: netdev@vger.kernel.org Cc: Eric Dumazet , linux-kernel@vger.kernel.org, Bobby Eshleman , Jakub Kicinski , Stefano Garzarella , virtualization@lists.linux.dev, Paolo Abeni , "Michael S. Tsirkin" , Simon Horman , "David S. Miller" Subject: [PATCH net 1/2] vsock: fix child netns mode initialization Date: Thu, 12 Feb 2026 21:59:15 +0100 Message-ID: <20260212205916.97533-2-sgarzare@redhat.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260212205916.97533-1-sgarzare@redhat.com> References: <20260212205916.97533-1-sgarzare@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Stefano Garzarella When a new network namespace is created, vsock_net_init() correctly initializes the namespace's mode by reading the parent's `child_ns_mode` via vsock_net_child_mode(). However, the `child_ns_mode` of the new namespace was always hardcoded to VSOCK_NET_MODE_GLOBAL, regardless of its own mode. This means that if a parent namespace has `child_ns_mode` set to "local", the child namespace correctly gets mode "local", but its `child_ns_mode` is reset to "global". As a result, further nested namespaces will incorrectly get mode "global" instead of inheriting "local", breaking the expected propagation of the mode through nested namespaces. Fix this by initializing `child_ns_mode` to the namespace's own mode, so the setting propagates correctly through all levels of nesting. Fixes: eafb64f40ca4 ("vsock: add netns to vsock core") Cc: bobbyeshleman@meta.com Signed-off-by: Stefano Garzarella --- net/vmw_vsock/af_vsock.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index 20ad2b2dc17b..3b629b4a0359 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -91,7 +91,8 @@ * - /proc/sys/net/vsock/ns_mode (read-only) reports the current namespace's * mode, which is set at namespace creation and immutable thereafter. * - /proc/sys/net/vsock/child_ns_mode (writable) controls what mode future - * child namespaces will inherit when created. The default is "global". + * child namespaces will inherit when created. The initial value matches + * the namespace's own ns_mode. * * Changing child_ns_mode only affects newly created namespaces, not the * current namespace or existing children. At namespace creation, ns_mode @@ -2912,7 +2913,7 @@ static void vsock_net_init(struct net *net) else net->vsock.mode = vsock_net_child_mode(current->nsproxy->net_ns); - net->vsock.child_ns_mode = VSOCK_NET_MODE_GLOBAL; + net->vsock.child_ns_mode = net->vsock.mode; } static __net_init int vsock_sysctl_init_net(struct net *net) -- 2.53.0