summaryrefslogtreecommitdiff
path: root/net
diff options
context:
space:
mode:
authorTyler Hicks <tyhicks@canonical.com>2018-07-21 00:56:51 +0300
committerDavid S. Miller <davem@davemloft.net>2018-07-21 09:44:35 +0300
commit3033fced2f689d4a870b3ba6a8a676db1261d262 (patch)
treea34ca7ad544097f8a999ccccde913e9edcc8fedd /net
parent9944e894c1266dc8515c82d1ff752d681215526b (diff)
downloadlinux-3033fced2f689d4a870b3ba6a8a676db1261d262.tar.xz
net-sysfs: require net admin in the init ns for setting tx_maxrate
An upcoming change will allow container root to open some /sys/class/net files for writing. The tx_maxrate attribute can result in changes to actual hardware devices so err on the side of caution by requiring CAP_NET_ADMIN in the init namespace in the corresponding attribute store operation. Signed-off-by: Tyler Hicks <tyhicks@canonical.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net')
-rw-r--r--net/core/net-sysfs.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/net/core/net-sysfs.c b/net/core/net-sysfs.c
index ffa1d18f2c2c..405c41ecb20b 100644
--- a/net/core/net-sysfs.c
+++ b/net/core/net-sysfs.c
@@ -1087,6 +1087,9 @@ static ssize_t tx_maxrate_store(struct netdev_queue *queue,
int err, index = get_netdev_queue_index(queue);
u32 rate = 0;
+ if (!capable(CAP_NET_ADMIN))
+ return -EPERM;
+
err = kstrtou32(buf, 10, &rate);
if (err < 0)
return err;