Skip to content
Commit 59cd7377 authored by Michael Weiß's avatar Michael Weiß Committed by Paolo Abeni
Browse files

net: openvswitch: allow conntrack in non-initial user namespace



Similar to the previous commit, the Netlink interface of the OVS
conntrack module was restricted to global CAP_NET_ADMIN by using
GENL_ADMIN_PERM. This is changed to GENL_UNS_ADMIN_PERM to support
unprivileged containers in non-initial user namespace.

Signed-off-by: default avatarMichael Weiß <michael.weiss@aisec.fraunhofer.de>
Signed-off-by: default avatarPaolo Abeni <pabeni@redhat.com>
parent 80393718
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment