[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20101024.160823.212694928.davem@davemloft.net>
Date: Sun, 24 Oct 2010 16:08:23 -0700 (PDT)
From: David Miller <davem@...emloft.net>
To: bazsi@...abit.hu
Cc: yoshfuji@...ux-ipv6.org, hidden@...abit.hu, netdev@...r.kernel.org,
netfilter-devel@...r.kernel.org, kaber@...sh.net
Subject: Re: [PATCH 5/9] tproxy: allow non-local binds of IPv6 sockets if
IP_TRANSPARENT is enabled
From: Balazs Scheidler <bazsi@...abit.hu>
Date: Sat, 23 Oct 2010 16:48:14 +0200
> IP_TRANSPARENT requires root (more precisely CAP_NET_ADMIN privielges)
> for IPV6.
>
> However as I see right now this check was missed from the IPv6
> implementation.
>
> Is that enough as a safeguard? e.g. something like this:
Applied, thanks everyone.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists