From 4684391cef6f2e5609be4aa7b5a7c446a3b5becb Mon Sep 17 00:00:00 2001 From: Greg Kroah-Hartman Date: Mon, 18 Dec 2023 19:07:26 +0000 Subject: [PATCH] Revert "drop_monitor: Require 'CAP_SYS_ADMIN' when joining "events" group" This reverts commit 4a341627a10959ef0db16f758bfd0d10fa9d73eb which is commit e03781879a0d524ce3126678d50a80484a513c4b upstream. It breaks the Android kernel abi and can be brought back in the future in an abi-safe way if it is really needed. Bug: 161946584 Change-Id: Iecbd6b6537bd4cd2d178d0afbdc7557e521429c5 Signed-off-by: Greg Kroah-Hartman --- include/net/genetlink.h | 2 -- net/core/drop_monitor.c | 4 +--- net/netlink/genetlink.c | 3 --- 3 files changed, 1 insertion(+), 8 deletions(-) diff --git a/include/net/genetlink.h b/include/net/genetlink.h index 2d52776def52..a8c9c8d1eb51 100644 --- a/include/net/genetlink.h +++ b/include/net/genetlink.h @@ -11,12 +11,10 @@ /** * struct genl_multicast_group - generic netlink multicast group * @name: name of the multicast group, names are per-family - * @cap_sys_admin: whether %CAP_SYS_ADMIN is required for binding */ struct genl_multicast_group { char name[GENL_NAMSIZ]; u8 flags; - u8 cap_sys_admin:1; }; struct genl_ops; diff --git a/net/core/drop_monitor.c b/net/core/drop_monitor.c index feb946c954b6..e8e8389ddc96 100644 --- a/net/core/drop_monitor.c +++ b/net/core/drop_monitor.c @@ -180,7 +180,7 @@ out: } static const struct genl_multicast_group dropmon_mcgrps[] = { - { .name = "events", .cap_sys_admin = 1 }, + { .name = "events", }, }; static void send_dm_alert(struct work_struct *work) @@ -1539,13 +1539,11 @@ static const struct genl_ops dropmon_ops[] = { .cmd = NET_DM_CMD_START, .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP, .doit = net_dm_cmd_trace, - .flags = GENL_ADMIN_PERM, }, { .cmd = NET_DM_CMD_STOP, .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP, .doit = net_dm_cmd_trace, - .flags = GENL_ADMIN_PERM, }, { .cmd = NET_DM_CMD_CONFIG_GET, diff --git a/net/netlink/genetlink.c b/net/netlink/genetlink.c index a03e16e06e29..34e3c8eb5911 100644 --- a/net/netlink/genetlink.c +++ b/net/netlink/genetlink.c @@ -1012,9 +1012,6 @@ static int genl_bind(struct net *net, int group) if ((grp->flags & GENL_UNS_ADMIN_PERM) && !ns_capable(net->user_ns, CAP_NET_ADMIN)) ret = -EPERM; - if (grp->cap_sys_admin && - !ns_capable(net->user_ns, CAP_SYS_ADMIN)) - ret = -EPERM; break; }