From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752175AbcEANjG (ORCPT ); Sun, 1 May 2016 09:39:06 -0400 Received: from mail-pf0-f170.google.com ([209.85.192.170]:34259 "EHLO mail-pf0-f170.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751086AbcEANjE convert rfc822-to-8bit (ORCPT ); Sun, 1 May 2016 09:39:04 -0400 From: Wang Shanker Content-Type: text/plain; charset=gb2312 Content-Transfer-Encoding: 8BIT Subject: [Question] Should `CAP_NET_ADMIN` be needed when opening `/dev/ppp`? Date: Sun, 1 May 2016 21:38:57 +0800 Message-Id: <2BEB0C68-EBC6-4A8F-A751-DE8F4A2C9D2C@gmail.com> Cc: linux-kernel@vger.kernel.org To: netdev@vger.kernel.org Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\)) X-Mailer: Apple Mail (2.3124) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, all. I¡¯ve recently met some problems when trying to create a pppoe network link inside a unprivileged container. There is a uid namespace which maps root inside to a normal user outside. There is also a separate net namespace in the container. I create a dev node inside the container and set right permission. However, `/dev/ppp` cannot get opened since the mapped normal user does not have `CAP_NET_ADMIN`. The related code is in `drivers/net/ppp/ppp_generic.c`: `int ppp_open()` ``` static int ppp_open(struct inode *inode, struct file *file) { /* * This could (should?) be enforced by the permissions on /dev/ppp. */ if (!capable(CAP_NET_ADMIN)) return -EPERM; return 0; } ``` I wonder why CAP_NET_ADMIN is needed here, rather than leaving it to the permission of the device node. If there is no need, I suggest that the CAP_NET_ADMIN check be removed.