mptcp: no admin perm to list endpoints
authorMatthieu Baerts (NGI0) <matttbe@kernel.org>
Mon, 4 Nov 2024 12:31:41 +0000 (13:31 +0100)
committerJakub Kicinski <kuba@kernel.org>
Wed, 6 Nov 2024 01:51:08 +0000 (17:51 -0800)
During the switch to YNL, the command to list all endpoints has been
accidentally restricted to users with admin permissions.

It looks like there are no reasons to have this restriction which makes
it harder for a user to quickly check if the endpoint list has been
correctly populated by an automated tool. Best to go back to the
previous behaviour then.

mptcp_pm_gen.c has been modified using ynl-gen-c.py:

   $ ./tools/net/ynl/ynl-gen-c.py --mode kernel \
     --spec Documentation/netlink/specs/mptcp_pm.yaml --source \
     -o net/mptcp/mptcp_pm_gen.c

The header file doesn't need to be regenerated.

Fixes: 1d0507f46843 ("net: mptcp: convert netlink from small_ops to ops")
Cc: stable@vger.kernel.org
Reviewed-by: Davide Caratti <dcaratti@redhat.com>
Reviewed-by: Mat Martineau <martineau@kernel.org>
Signed-off-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://patch.msgid.link/20241104-net-mptcp-misc-6-12-v1-1-c13f2ff1656f@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Documentation/netlink/specs/mptcp_pm.yaml
net/mptcp/mptcp_pm_gen.c

index 30d8342..dc190bf 100644 (file)
@@ -293,7 +293,6 @@ operations:
       doc: Get endpoint information
       attribute-set: attr
       dont-validate: [ strict ]
-      flags: [ uns-admin-perm ]
       do: &get-addr-attrs
         request:
           attributes:
index c30a2a9..bfb37c5 100644 (file)
@@ -112,7 +112,6 @@ const struct genl_ops mptcp_pm_nl_ops[11] = {
                .dumpit         = mptcp_pm_nl_get_addr_dumpit,
                .policy         = mptcp_pm_get_addr_nl_policy,
                .maxattr        = MPTCP_PM_ATTR_TOKEN,
-               .flags          = GENL_UNS_ADMIN_PERM,
        },
        {
                .cmd            = MPTCP_PM_CMD_FLUSH_ADDRS,