No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Johannes Wiesböck 509da3463f rtnetlink: Allow deleting FDB entries in user namespace
[ Upstream commit bf29555f5bdc017bac22ca66fcb6c9f46ec8788f ]

Creating FDB entries is possible from a non-initial user namespace when
having CAP_NET_ADMIN, yet, when deleting FDB entries, processes receive
an EPERM because the capability is always checked against the initial
user namespace. This restricts the FDB management from unprivileged
containers.

Drop the netlink_capable check in rtnl_fdb_del as it was originally
dropped in c5c351088a and reintroduced in 1690be63a2 without
intention.

This patch was tested using a container on GyroidOS, where it was
possible to delete FDB entries from an unprivileged user namespace and
private network namespace.

Fixes: 1690be63a2 ("bridge: Add vlan support to static neighbors")
Reviewed-by: Michael Weiß <michael.weiss@aisec.fraunhofer.de>
Tested-by: Harshal Gohel <hg@simonwunderlich.de>
Signed-off-by: Johannes Wiesböck <johannes.wiesboeck@aisec.fraunhofer.de>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Reviewed-by: Nikolay Aleksandrov <razor@blackwall.org>
Link: https://patch.msgid.link/20251015201548.319871-1-johannes.wiesboeck@aisec.fraunhofer.de
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-29 13:59:59 +01:00
arch m68k: bitops: Fix find_*_bit() signatures 2025-10-29 13:59:58 +01:00
block block: use int to store blk_stack_limits() return value 2025-10-29 13:59:46 +01:00
certs
crypto crypto: essiv - Check ssize for decryption and in-place encryption 2025-10-29 13:59:52 +01:00
Documentation fs: Add 'initramfs_options' to set initramfs mount options 2025-10-29 13:59:55 +01:00
drivers tg3: prevent use of uninitialized remote_adv and local_adv variables 2025-10-29 13:59:57 +01:00
fs hfsplus: return EIO when type of hidden directory mismatch in hfsplus_fill_super() 2025-10-29 13:59:58 +01:00
include net: add ndo_fdb_del_bulk 2025-10-29 13:59:59 +01:00
init bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
ipc
kernel sched/fair: Fix pelt lost idle time detection 2025-10-29 13:59:57 +01:00
lib lib/genalloc: fix device leak in of_gen_pool_get() 2025-10-29 13:59:53 +01:00
LICENSES
mm mm: hugetlb: avoid soft lockup when mprotect to large memory area 2025-10-29 13:59:50 +01:00
net rtnetlink: Allow deleting FDB entries in user namespace 2025-10-29 13:59:59 +01:00
samples samples: mei: Fix building on musl libc 2025-08-28 16:21:19 +02:00
scripts randstruct: gcc-plugin: Fix attribute addition 2025-09-09 18:44:01 +02:00
security securityfs: don't pin dentries twice, once is enough... 2025-08-28 16:21:24 +02:00
sound ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings 2025-10-29 13:59:57 +01:00
tools rseq/selftests: Use weak symbol reference, not definition, to link with glibc 2025-10-29 13:59:54 +01:00
usr kbuild: hdrcheck: fix cross build with clang 2025-07-17 18:24:51 +02:00
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS platform: Add Surface platform directory 2025-06-27 11:02:56 +01:00
Makefile Linux 5.4.300 2025-10-02 13:34:35 +02:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.