From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 52F9942EEDF for ; Tue, 9 Jun 2026 16:31:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781022683; cv=none; b=p4YlEgdAUaOrcvGbyvW6Aw+Dv54nk2hZ1sAGTur7Dywv6aCE3h3aTaKIddT2QctRKOCChIbKy51TRToBHpCgw+U/pGQ3s2lGw+NlGEESCg1Sbu+7nWiDAJg/+l1tHGRhip0EGzm/TvjH8NDwJiwjCFT0mgPiwYjDNTWFlFzxbA4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781022683; c=relaxed/simple; bh=rIznTwLb+grN+SEa4jmN1Kf+ePS7qTBPFnyTDfo7REU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=HQIycTqREZ4uh3AFJkNT6/hkM54gIAc2PYKhFSKefkHTUg0gOkdjbCwWlMmav3yxhtqA9b2DMyxNpusmPWLXcidwZIOOMOsG/zy00DZ8N/lwf+QxXkFHGSo+y1pv8Ywp/9HrwrvTjrlYjtZotBtjNRhomT1x+zUsoqEr/KhvoO4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=hwydTfql; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="hwydTfql" Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2c0c3184c71so44122925ad.1 for ; Tue, 09 Jun 2026 09:31:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781022681; x=1781627481; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=NOScBN8qzHidY1x3Y7+FW8ZQCw6XnOMJJfJFMyByHk0=; b=hwydTfqlHJfSLNmf5j0KG/3V/OJCQPoj1Izx0Pt/mehPHG1lafPm5iehy9Oz+MCY08 wOBfKzhXjsJP9LetdV7iLu4IoxNlCPtcVqlPEK7NZMbou6EUjENz3SoR4ZhzaJrFWYv4 G+DOd1KTIxfOVdupUD6emfeAcvzpuwysHETOGus1WcVNCVxnHvpGqctzlymeavADNqOv qbSJ89styy5c1h8nnb6w89J3CgfpDTrd4u4uZDZylnpTzwqETehekdnzlza44pSR2E0q ZJxazG3z8v1ZJhNg9zedC3DUbdtRu2o9xgVE3tsVFEE9r1wNiLahlRGdWniGuPpZaLh/ EIlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781022681; x=1781627481; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=NOScBN8qzHidY1x3Y7+FW8ZQCw6XnOMJJfJFMyByHk0=; b=ogBSjQLwOGq/wmFK8fOZfyy3+MHBMOwObo/csv9ho2lb5eQVr6krpiopPmzG9metbg 6LUchTesgpQtmsBe3wh/gFPe2cXqGJyix5iWbNL5MixxlkWMRWWJcgVw+/aWu1VDI6+0 d5hq/ly3SsuKldKN77VXdIjt/Vjxalf26JM84w2DuBbil7TzuzHpECBkOOI48NIaOo4C OmIDwzYiUAHpuFDz3sNtvEqVRo9eLP/crVJqft8fqZ5mowMLnhSbcvJCI5AFMYOUpM1d 2/XeOPZlQxtA4YxdUaZaTDaHGAw+muw/GkkxXOHQtX3hBW6XViJVb9N0u2EOqAQ/aJuw 3lAA== X-Forwarded-Encrypted: i=1; AFNElJ9uhy6LM4CkNOjFMeSrRh8TEVmMvKC1R91vUT03j8+eQo+/0vI6vH7hknKnzC5gxwqEn+Hx/WvNPwhlxcc=@vger.kernel.org X-Gm-Message-State: AOJu0Yw02yYSm7DU9xes2zkWHLy3cQei4+pad2C763vtfQ5dDiw3uC7i vbllCcNy1Du95oS03cmOeWHLvKAggOINUJCGAIz2rm1lgroRl9/qpXM6 X-Gm-Gg: Acq92OGsRafg9hPB4BdEKYSy3xo7ZCd2NyXEcUOXV9aFYg6pidj6e1sgZj595TeRm28 GkcBQvuhR6A+HkshgAxGz6alM98Li8TYWkSJhGAeHCQr6hu9DnS7fqfEpaSDkMgJSj7/j0ZelVL Px3VgGJSfjQjJY1Wg41M5TdfCjsMI4sqism4TObNR0XKI5KqWi+6ba2kN8VuZsKGtIgcF91IbEl 9xhwptwbApejRaOWVGASR8dkA32CETwNOMQrzgGwrAVT2gOE/TdJ2u3h2xxPsnZnykycFsbrpIe IDb75HP6E6lqpIoLBSM7Az+lehtS6E/IG0BLLSaMGBXoKsWfs7l2IdbtY2IrHiNpFaSJDmiZb/k PdvknM+58lNMv3T33gGyYVaH7MUyxpRllCBUwvkpf1MwMM6eo/dFrEBVQ7xMYgGHWupa/RTxVaQ H3b2Bem3o90omNlBSVWDHAB35wNof/zl4/lidFvjd+AJOgEX5lMmLxymYoaYU= X-Received: by 2002:a17:902:ea09:b0:2bc:8f9a:3642 with SMTP id d9443c01a7336-2c1e7e6eee0mr235696225ad.16.1781022681487; Tue, 09 Jun 2026 09:31:21 -0700 (PDT) Received: from csl-conti-dell7858.ntu.edu.sg ([155.69.195.57]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2c16629d042sm227710195ad.60.2026.06.09.09.31.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 09 Jun 2026 09:31:20 -0700 (PDT) From: Maoyi Xie To: "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: David Ahern , Kuniyuki Iwashima , Xiao Liang , Steffen Klassert , Herbert Xu , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net v4 1/7] net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink Date: Wed, 10 Jun 2026 00:31:04 +0800 Message-Id: <20260609163110.1717419-2-maoyixie.tju@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260609163110.1717419-1-maoyixie.tju@gmail.com> References: <20260609163110.1717419-1-maoyixie.tju@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit A tunnel changelink rewrites the tunnel in its creation netns. After an IFLA_NET_NS_FD migration that netns is not the caller's. The rtnl changelink path only checks CAP_NET_ADMIN against the caller's netns. A caller with caps only in its current netns can then rewrite a tunnel that lives in another netns, and it picks the endpoint addresses. Add net_admin_capable(). It requires CAP_NET_ADMIN in the tunnel's netns and is skipped when that netns is the device's current netns, where the rtnl path already checked the cap. The other patches in this series use the same helper. Gate ipgre_changelink() and erspan_changelink() with it. The check is at the top of the op, before any attribute is parsed, because the parsers update live tunnel fields first. ipgre_netlink_parms() sets t->collect_md before ip_tunnel_changelink() runs. Commit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().") added the same check on the ioctl path. This adds it on RTM_NEWLINK. Reported-by: Xiao Liang Closes: https://lore.kernel.org/netdev/CABAhCOSzP1vaThGV35_VnsRCb=87_CPjPVsTHbq905k8A+BuUg@mail.gmail.com/ Fixes: d0f418516022 ("net, ip_tunnel: fix namespaces move") Cc: stable@vger.kernel.org Signed-off-by: Maoyi Xie --- include/net/net_namespace.h | 18 ++++++++++++++++++ net/ipv4/ip_gre.c | 6 ++++++ 2 files changed, 24 insertions(+) diff --git a/include/net/net_namespace.h b/include/net/net_namespace.h index 80de5e98a66d..17fb71a78cb6 100644 --- a/include/net/net_namespace.h +++ b/include/net/net_namespace.h @@ -358,6 +358,24 @@ static inline bool net_initialized(const struct net *net) return READ_ONCE(net->list.next); } +/** + * net_admin_capable - test for CAP_NET_ADMIN over a network namespace + * @net: namespace whose state the operation would change + * @cur: namespace the operation runs in, e.g. dev_net(dev) + * + * Returns true when @net is @cur, where CAP_NET_ADMIN was already + * checked for the running namespace, or when the caller holds + * CAP_NET_ADMIN over @net. rtnl changelink paths use this: a device can + * be moved so its state lives in a namespace other than the one the + * request runs in, and the cap must then be held over that namespace. + */ +static inline bool net_admin_capable(const struct net *net, + const struct net *cur) +{ + return net_eq(net, cur) || + ns_capable(net->user_ns, CAP_NET_ADMIN); +} + static inline void __netns_tracker_alloc(struct net *net, netns_tracker *tracker, bool refcounted, diff --git a/net/ipv4/ip_gre.c b/net/ipv4/ip_gre.c index 169e2921a851..040a0ef95184 100644 --- a/net/ipv4/ip_gre.c +++ b/net/ipv4/ip_gre.c @@ -1457,6 +1457,9 @@ static int ipgre_changelink(struct net_device *dev, struct nlattr *tb[], __u32 fwmark = t->fwmark; int err; + if (!net_admin_capable(t->net, dev_net(dev))) + return -EPERM; + err = ipgre_newlink_encap_setup(dev, data); if (err) return err; @@ -1486,6 +1489,9 @@ static int erspan_changelink(struct net_device *dev, struct nlattr *tb[], __u32 fwmark = t->fwmark; int err; + if (!net_admin_capable(t->net, dev_net(dev))) + return -EPERM; + err = ipgre_newlink_encap_setup(dev, data); if (err) return err; -- 2.34.1