summaryrefslogtreecommitdiffstats
path: root/main/linux-virt-grsec/sysctl_lxc.patch
diff options
context:
space:
mode:
authorLeonardo Arena <rnalrd@alpinelinux.org>2013-12-13 14:53:19 +0000
committerLeonardo Arena <rnalrd@alpinelinux.org>2013-12-13 14:54:01 +0000
commit68116ecd619f49779ae42c65a4df89e511e525aa (patch)
tree953a0568201f5e5beaf54d952aa2506f421c2937 /main/linux-virt-grsec/sysctl_lxc.patch
parent15c4f5644f5a4ceabf48320bfc7a11747d8093fa (diff)
downloadaports-68116ecd619f49779ae42c65a4df89e511e525aa.tar.bz2
aports-68116ecd619f49779ae42c65a4df89e511e525aa.tar.xz
main/linux-virt-grsec: upgrade to version 3.12.4
Diffstat (limited to 'main/linux-virt-grsec/sysctl_lxc.patch')
-rw-r--r--main/linux-virt-grsec/sysctl_lxc.patch31
1 files changed, 0 insertions, 31 deletions
diff --git a/main/linux-virt-grsec/sysctl_lxc.patch b/main/linux-virt-grsec/sysctl_lxc.patch
deleted file mode 100644
index 56279aa03..000000000
--- a/main/linux-virt-grsec/sysctl_lxc.patch
+++ /dev/null
@@ -1,31 +0,0 @@
-This patch allows guests to set /proc/sys/net/*/ip_forward without
-needing CAP_SYS_ADMIN.
-
-diff --git a/fs/proc/proc_sysctl.c b/fs/proc/proc_sysctl.c
-index 1e6dc7e..0a5638b 100644
---- a/fs/proc/proc_sysctl.c
-+++ b/fs/proc/proc_sysctl.c
-@@ -11,6 +11,7 @@
- #include <linux/namei.h>
- #include <linux/mm.h>
- #include <linux/module.h>
-+#include <linux/nsproxy.h>
- #include "internal.h"
-
- extern int gr_handle_chroot_sysctl(const int op);
-@@ -521,8 +522,13 @@ static ssize_t proc_sys_call_handler(struct file *filp, void __user *buf,
- dput(filp->f_path.dentry);
- if (!gr_acl_handle_open(filp->f_path.dentry, filp->f_path.mnt, op))
- goto out;
-- if (write && !capable(CAP_SYS_ADMIN))
-- goto out;
-+ if (write) {
-+ if (current->nsproxy->net_ns != table->extra2) {
-+ if (!capable(CAP_SYS_ADMIN))
-+ goto out;
-+ } else if (!nsown_capable(CAP_NET_ADMIN))
-+ goto out;
-+ }
- #endif
-
- /* careful: calling conventions are nasty here */