Commit 3ba0032a authored by Michal Koutný's avatar Michal Koutný Committed by Pablo Neira Ayuso
Browse files

netfilter: xt_cgroup: Make it independent from net_cls

The xt_group matching supports the default hierarchy since commit
c38c4597 ("netfilter: implement xt_cgroup cgroup2 path match").
The cgroup v1 matching (based on clsid) and cgroup v2 matching (based on
path) are rather independent. Downgrade the Kconfig dependency to
mere CONFIG_SOCK_GROUP_DATA so that xt_group can be built even without
CONFIG_NET_CLS_CGROUP for path matching.
Also add a message for users when they attempt to specify any clsid.

Link: https://lists.opensuse.org/archives/list/kernel@lists.opensuse.org/thread/S23NOILB7MUIRHSKPBOQKJHVSK26GP6X/


Cc: Jan Engelhardt <ej@inai.de>
Cc: Florian Westphal <fw@strlen.de>
Signed-off-by: default avatarMichal Koutný <mkoutny@suse.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent f4293c2b
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -1180,7 +1180,7 @@ config NETFILTER_XT_MATCH_CGROUP
	tristate '"control group" match support'
	depends on NETFILTER_ADVANCED
	depends on CGROUPS
	select CGROUP_NET_CLASSID
	select SOCK_CGROUP_DATA
	help
	Socket/process control group matching allows you to match locally
	generated packets based on which net_cls control group processes
+17 −0
Original line number Diff line number Diff line
@@ -23,6 +23,8 @@ MODULE_DESCRIPTION("Xtables: process control group matching");
MODULE_ALIAS("ipt_cgroup");
MODULE_ALIAS("ip6t_cgroup");

#define NET_CLS_CLASSID_INVALID_MSG "xt_cgroup: classid invalid without net_cls cgroups\n"

static int cgroup_mt_check_v0(const struct xt_mtchk_param *par)
{
	struct xt_cgroup_info_v0 *info = par->matchinfo;
@@ -30,6 +32,11 @@ static int cgroup_mt_check_v0(const struct xt_mtchk_param *par)
	if (info->invert & ~1)
		return -EINVAL;

	if (!IS_ENABLED(CONFIG_CGROUP_NET_CLASSID)) {
		pr_info(NET_CLS_CLASSID_INVALID_MSG);
		return -EINVAL;
	}

	return 0;
}

@@ -51,6 +58,11 @@ static int cgroup_mt_check_v1(const struct xt_mtchk_param *par)
		return -EINVAL;
	}

	if (info->has_classid && !IS_ENABLED(CONFIG_CGROUP_NET_CLASSID)) {
		pr_info(NET_CLS_CLASSID_INVALID_MSG);
		return -EINVAL;
	}

	info->priv = NULL;
	if (info->has_path) {
		cgrp = cgroup_get_from_path(info->path);
@@ -83,6 +95,11 @@ static int cgroup_mt_check_v2(const struct xt_mtchk_param *par)
		return -EINVAL;
	}

	if (info->has_classid && !IS_ENABLED(CONFIG_CGROUP_NET_CLASSID)) {
		pr_info(NET_CLS_CLASSID_INVALID_MSG);
		return -EINVAL;
	}

	info->priv = NULL;
	if (info->has_path) {
		cgrp = cgroup_get_from_path(info->path);