platform-linux: allow netlink messages from non-privileged user namespaces
Just check they're from kernel.
This commit is contained in:
@@ -4565,10 +4565,9 @@ verify_source (struct nl_msg *msg, gpointer user_data)
|
|||||||
{
|
{
|
||||||
struct ucred *creds = nlmsg_get_creds (msg);
|
struct ucred *creds = nlmsg_get_creds (msg);
|
||||||
|
|
||||||
if (!creds || creds->pid || creds->uid || creds->gid) {
|
if (!creds || creds->pid) {
|
||||||
if (creds)
|
if (creds)
|
||||||
warning ("netlink: received non-kernel message (pid %d uid %d gid %d)",
|
warning ("netlink: received non-kernel message (pid %d)", creds->pid);
|
||||||
creds->pid, creds->uid, creds->gid);
|
|
||||||
else
|
else
|
||||||
warning ("netlink: received message without credentials");
|
warning ("netlink: received message without credentials");
|
||||||
return NL_STOP;
|
return NL_STOP;
|
||||||
|
Reference in New Issue
Block a user