From patchwork Sun Mar 12 23:01:35 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Hannes Frederic Sowa X-Patchwork-Id: 737915 X-Patchwork-Delegate: davem@davemloft.net Return-Path: X-Original-To: patchwork-incoming@ozlabs.org Delivered-To: patchwork-incoming@ozlabs.org Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 3vhGjz2fG6z9s78 for ; Mon, 13 Mar 2017 10:02:47 +1100 (AEDT) Authentication-Results: ozlabs.org; dkim=pass (1024-bit key; unprotected) header.d=stressinduktion.org header.i=@stressinduktion.org header.b="JbpdlGBZ"; dkim=pass (1024-bit key; unprotected) header.d=messagingengine.com header.i=@messagingengine.com header.b="ncygk6Xe"; dkim-atps=neutral Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S935720AbdCLXCo (ORCPT ); Sun, 12 Mar 2017 19:02:44 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:39683 "EHLO out1-smtp.messagingengine.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S935604AbdCLXCI (ORCPT ); Sun, 12 Mar 2017 19:02:08 -0400 Received: from compute7.internal (compute7.nyi.internal [10.202.2.47]) by mailout.nyi.internal (Postfix) with ESMTP id 0BF9E20757 for ; Sun, 12 Mar 2017 19:02:02 -0400 (EDT) Received: from frontend2 ([10.202.2.161]) by compute7.internal (MEProxy); Sun, 12 Mar 2017 19:02:02 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= stressinduktion.org; h=date:from:in-reply-to:message-id :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=8ydnlUuPNTzseSTNN+UXSxVzXiQ=; b=JbpdlG BZTgZU/9uNr4fgoa7NRahlBJ8aLc2bihtkNA9R5VI3tQ6f/DmgY1FSEnGbj2Mwa1 9JrA5pEuXhfiOOQfRQm+RwB/iNKr9rcupt0gmmPTA+vcsOrLNrtCSawNYpMgNF6H ixG97yOmAiBH/b6G27QhA/14qin5s+lJJhYsY= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=date:from:in-reply-to:message-id :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=smtpout; bh=8ydnlUuPNTzseSTNN+UXSxVzXiQ=; b=ncygk 6Xeakb8qvCshPYikWOspgDPS1eaSTd6gFyqzf10RtDgJKk00vkJjCyQ0VUoXBOoH Y47I51NVMiFsW7doeJssuY56x0QQxg5ei5niwg74JMllc1I0VAZLKpqVOnB018xG JSgYTKNOJd8c4n3hpK5fruC0HpZH9VwWWROXxg= X-ME-Sender: X-Sasl-enc: 0OS/HYN3IHYxA6bt70H8aM2wkKuHiurY8UEiGTzFelCX 1489359721 Received: from m.localhost.localhost (unknown [213.55.211.72]) by mail.messagingengine.com (Postfix) with ESMTPA id 3DF322423E for ; Sun, 12 Mar 2017 19:02:01 -0400 (EDT) From: Hannes Frederic Sowa To: netdev@vger.kernel.org Subject: [PATCH net-next RFC v1 11/27] afnetns: validate afnetns in inet_allow_bind Date: Mon, 13 Mar 2017 00:01:35 +0100 Message-Id: <20170312230151.5185-12-hannes@stressinduktion.org> X-Mailer: git-send-email 2.9.3 In-Reply-To: <20170312230151.5185-1-hannes@stressinduktion.org> References: <20170312230151.5185-1-hannes@stressinduktion.org> Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org Signed-off-by: Hannes Frederic Sowa --- net/ipv4/af_inet.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c index aee599e23137e7..5f11399bafd16f 100644 --- a/net/ipv4/af_inet.c +++ b/net/ipv4/af_inet.c @@ -453,6 +453,17 @@ int inet_allow_bind(struct sock *sk, __be32 addr) chk_addr_ret != RTN_BROADCAST) return -EADDRNOTAVAIL; + if (chk_addr_ret == RTN_LOCAL && + net_afnetns(net) != sock_afnetns(sk)) { + struct afnetns *afnetns; + + rcu_read_lock(); + afnetns = ifa_find_afnetns_rcu(net, addr); + if (afnetns != sock_afnetns(sk)) + chk_addr_ret = -EADDRNOTAVAIL; + rcu_read_unlock(); + } + return chk_addr_ret; } EXPORT_SYMBOL(inet_allow_bind);