netfilter: xt_qtaguid: recognize IPV6 interfaces. root is procfs privileged.
authorJP Abgrall <jpa@google.com>
Tue, 9 Aug 2011 18:53:11 +0000 (11:53 -0700)
committermgross <mark.gross@intel.com>
Wed, 9 Nov 2011 20:22:41 +0000 (12:22 -0800)
commit203a4f19fbe542ae2b3557e1db700b06f8515697
tree0c62bfa9d45822acf380240473655ae5cc82d211
parent58fea40ecd0544a28bd69fcccf6e177d6f58de81
netfilter: xt_qtaguid: recognize IPV6 interfaces. root is procfs privileged.

* Allow tracking interfaces that only have an ipv6 address.
  Deal with ipv6 notifier chains that do NETDEV_UP without the rtnl_lock()
* Allow root all access to procfs ctrl/stats.
  To disable all checks:
    echo 0 > /sys/module/xt_qtaguid/parameters/ctrl_write_gid
    echo 0 > /sys/module/xt_qtaguid/parameters/stats_readall_gid
* Add CDEBUG define to enable pr_debug output specific to
    procfs ctrl/stats access.

Change-Id: I9a469511d92fe42734daff6ea2326701312a161b
Signed-off-by: JP Abgrall <jpa@google.com>
net/netfilter/xt_qtaguid.c