[NET]: Make /proc/net per network namespace
This patch makes /proc/net per network namespace. It modifies the global variables proc_net and proc_net_stat to be per network namespace. The proc_net file helpers are modified to take a network namespace argument, and all of their callers are fixed to pass &init_net for that argument. This ensures that all of the /proc/net files are only visible and usable in the initial network namespace until the code behind them has been updated to be handle multiple network namespaces. Making /proc/net per namespace is necessary as at least some files in /proc/net depend upon the set of network devices which is per network namespace, and even more files in /proc/net have contents that are relevant to a single network namespace. Signed-off-by: Eric W. Biederman <ebiederm@xmission.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Esse commit está contido em:

commit de
David S. Miller

pai
07feaebfcc
commit
457c4cbc5a
@@ -49,6 +49,7 @@
|
||||
#include <linux/netfilter.h>
|
||||
#include <linux/netfilter_ipv6.h>
|
||||
|
||||
#include <net/net_namespace.h>
|
||||
#include <net/sock.h>
|
||||
#include <net/snmp.h>
|
||||
|
||||
@@ -2658,8 +2659,8 @@ int __init igmp6_init(struct net_proto_family *ops)
|
||||
np->hop_limit = 1;
|
||||
|
||||
#ifdef CONFIG_PROC_FS
|
||||
proc_net_fops_create("igmp6", S_IRUGO, &igmp6_mc_seq_fops);
|
||||
proc_net_fops_create("mcfilter6", S_IRUGO, &igmp6_mcf_seq_fops);
|
||||
proc_net_fops_create(&init_net, "igmp6", S_IRUGO, &igmp6_mc_seq_fops);
|
||||
proc_net_fops_create(&init_net, "mcfilter6", S_IRUGO, &igmp6_mcf_seq_fops);
|
||||
#endif
|
||||
|
||||
return 0;
|
||||
@@ -2671,7 +2672,7 @@ void igmp6_cleanup(void)
|
||||
igmp6_socket = NULL; /* for safety */
|
||||
|
||||
#ifdef CONFIG_PROC_FS
|
||||
proc_net_remove("mcfilter6");
|
||||
proc_net_remove("igmp6");
|
||||
proc_net_remove(&init_net, "mcfilter6");
|
||||
proc_net_remove(&init_net, "igmp6");
|
||||
#endif
|
||||
}
|
||||
|
Referência em uma nova issue
Block a user