From: Cong Wang <amwang@redhat.com>
To: netdev@vger.kernel.org
Cc: David Miller <davem@davemloft.net>, Cong Wang <amwang@redhat.com>
Subject: [Patch net-next v7 5/6] vxlan: respect disable_ipv6 sysctl
Date: Tue, 30 Apr 2013 16:43:14 +0800 [thread overview]
Message-ID: <1367311395-15891-6-git-send-email-amwang@redhat.com> (raw)
In-Reply-To: <1367311395-15891-1-git-send-email-amwang@redhat.com>
From: Cong Wang <amwang@redhat.com>
When disable_ipv6 is set, we should not allow IPv6 vxlan
device to be created on top of it.
Cc: David Miller <davem@davemloft.net>
Signed-off-by: Cong Wang <amwang@redhat.com>
---
drivers/net/vxlan.c | 12 ++++++++++++
1 files changed, 12 insertions(+), 0 deletions(-)
diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index bb39e67..ec1007a 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -1671,6 +1671,7 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
struct vxlan_rdst *dst = &vxlan->default_dst;
__u32 vni;
int err;
+ bool use_ipv6 = false;
if (!data[IFLA_VXLAN_ID])
return -EINVAL;
@@ -1692,6 +1693,7 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
nla_memcpy(&dst->remote_ip.sin6.sin6_addr, data[IFLA_VXLAN_GROUP6],
sizeof(struct in6_addr));
dst->remote_ip.sa.sa_family = AF_INET6;
+ use_ipv6 = true;
#else
return -EPFNOSUPPORT;
#endif
@@ -1707,6 +1709,7 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
nla_memcpy(&vxlan->saddr.sin6.sin6_addr, data[IFLA_VXLAN_LOCAL6],
sizeof(struct in6_addr));
vxlan->saddr.sa.sa_family = AF_INET6;
+ use_ipv6 = true;
#else
return -EPFNOSUPPORT;
#endif
@@ -1722,6 +1725,15 @@ static int vxlan_newlink(struct net *net, struct net_device *dev,
return -ENODEV;
}
+#if IS_ENABLED(CONFIG_IPV6)
+ if (use_ipv6) {
+ struct inet6_dev *idev = in6_dev_get(lowerdev);
+ if (idev && idev->cnf.disable_ipv6)
+ return -EPERM;
+ }
+#else
+ BUG_ON(use_ipv6);
+#endif
if (!tb[IFLA_MTU])
dev->mtu = lowerdev->mtu - VXLAN_HEADROOM;
--
1.7.7.6
next prev parent reply other threads:[~2013-04-30 8:44 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-04-30 8:43 [Patch net-next v7 0/6] vxlan: add ipv6 support Cong Wang
2013-04-30 8:43 ` [Patch net-next v7 1/6] vxlan: defer vxlan init as late as possible Cong Wang
2013-04-30 8:43 ` [Patch net-next v7 2/6] ipv6: export a stub for ipv6_sock_mc_join and ipv6_sock_mc_drop Cong Wang
2013-04-30 8:43 ` [Patch net-next v7 3/6] ipv6: export in6addr_loopback to modules Cong Wang
2013-04-30 8:43 ` [Patch net-next v7 4/6] vxlan: add ipv6 support Cong Wang
2013-04-30 9:17 ` Bjørn Mork
2013-04-30 9:25 ` Cong Wang
2013-04-30 10:33 ` Bjørn Mork
2013-04-30 19:06 ` David Miller
2013-05-02 8:05 ` Cong Wang
2013-05-02 8:10 ` David Miller
2013-05-02 12:45 ` Bjørn Mork
2013-05-03 3:02 ` Cong Wang
2013-04-30 19:05 ` David Miller
2013-05-02 7:55 ` Cong Wang
2013-04-30 9:38 ` Cong Wang
2013-04-30 18:58 ` David Miller
2013-04-30 19:04 ` David Miller
2013-04-30 8:43 ` Cong Wang [this message]
2013-04-30 12:27 ` [Patch net-next v7 5/6] vxlan: respect disable_ipv6 sysctl Sergei Shtylyov
2013-04-30 8:43 ` [Patch net-next v7 6/6] ipv6: Add generic UDP Tunnel segmentation Cong Wang
2013-04-30 19:00 ` [Patch net-next v7 0/6] vxlan: add ipv6 support David Miller
2013-05-02 7:02 ` Cong Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1367311395-15891-6-git-send-email-amwang@redhat.com \
--to=amwang@redhat.com \
--cc=davem@davemloft.net \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).