From: Maoyi Xie <maoyixie.tju@gmail.com>
To: "David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: David Ahern <dsahern@kernel.org>,
Kuniyuki Iwashima <kuniyu@google.com>,
Xiao Liang <shaw.leon@gmail.com>,
Steffen Klassert <steffen.klassert@secunet.com>,
Herbert Xu <herbert@gondor.apana.org.au>,
Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: [PATCH net v4 0/7] net: require CAP_NET_ADMIN in the device netns for tunnel changelink
Date: Wed, 10 Jun 2026 00:31:03 +0800 [thread overview]
Message-ID: <20260609163110.1717419-1-maoyixie.tju@gmail.com> (raw)
A tunnel changelink rewrites the tunnel in its creation netns. After an
IFLA_NET_NS_FD migration that creation netns is not the caller's. The
rtnl changelink path only checks CAP_NET_ADMIN against the caller's
netns, so a caller with caps only in its current netns can rewrite a
tunnel that lives in the creation netns, and it picks the endpoint
addresses. Commit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in
vti6_siocdevprivate().") added the same check on the ioctl path. This
series adds it on the RTM_NEWLINK path.
Each changelink is gated at the top of the op, before any attribute is
parsed, because the per-type parsers can update live tunnel fields first.
For example ipgre_netlink_parms() sets t->collect_md before
ip_tunnel_changelink() runs. The check is skipped when the creation netns
equals the device's current netns, where the rtnl path already checked
the cap.
This is the same fix as v3, restructured after Paolo's review:
- Split into one patch per tunnel, each with its own Fixes tag.
- Move the repeated check into a helper, net_admin_capable(), added in
patch 1 and used by the rest of the series.
Tested on net/main. For every tunnel type in the series a migrated
fake-root changelink is rejected with EPERM. For vti6 SIOCGETTUNNEL
confirms the creation netns hash is left unchanged. Legit non-migrated
changelinks still succeed.
v3: https://lore.kernel.org/netdev/20260604125055.3254652-1-maoyixie.tju@gmail.com/
v2: https://lore.kernel.org/netdev/20260601034148.1272080-1-maoyixie.tju@gmail.com/
v1: https://lore.kernel.org/netdev/20260527070824.2677331-1-maoyixie.tju@gmail.com/
Maoyi Xie (7):
net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
net: ipip: require CAP_NET_ADMIN in the device netns for changelink
net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink
net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for
changelink
net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink
net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink
xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for
changelink
include/net/net_namespace.h | 18 ++++++++++++++++++
net/ipv4/ip_gre.c | 6 ++++++
net/ipv4/ip_vti.c | 3 +++
net/ipv4/ipip.c | 3 +++
net/ipv6/ip6_gre.c | 6 ++++++
net/ipv6/ip6_tunnel.c | 3 +++
net/ipv6/ip6_vti.c | 3 +++
net/xfrm/xfrm_interface_core.c | 3 +++
8 files changed, 45 insertions(+)
base-commit: 0aa05daef7848a5ac11158949dc73cd741995dc1
--
2.34.1
next reply other threads:[~2026-06-09 16:31 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-09 16:31 Maoyi Xie [this message]
2026-06-09 16:31 ` [PATCH net v4 1/7] net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink Maoyi Xie
2026-06-11 5:25 ` Kuniyuki Iwashima
2026-06-09 16:31 ` [PATCH net v4 2/7] net: ipip: " Maoyi Xie
2026-06-09 16:31 ` [PATCH net v4 3/7] net: ip_vti: " Maoyi Xie
2026-06-09 16:31 ` [PATCH net v4 4/7] net: ip6_tunnel: " Maoyi Xie
2026-06-09 16:31 ` [PATCH net v4 5/7] net: ip6_gre: " Maoyi Xie
2026-06-09 16:31 ` [PATCH net v4 6/7] net: ip6_vti: " Maoyi Xie
2026-06-09 16:31 ` [PATCH net v4 7/7] xfrm: xfrm_interface: " Maoyi Xie
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260609163110.1717419-1-maoyixie.tju@gmail.com \
--to=maoyixie.tju@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=herbert@gondor.apana.org.au \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=shaw.leon@gmail.com \
--cc=stable@vger.kernel.org \
--cc=steffen.klassert@secunet.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®