]> exis.tech > repos - linux.git/commitdiff
ip6_vti: set netns_immutable on the fallback device.
authorEric Dumazet <edumazet@google.com>
Mon, 8 Jun 2026 15:59:18 +0000 (15:59 +0000)
committerJakub Kicinski <kuba@kernel.org>
Wed, 10 Jun 2026 01:15:47 +0000 (18:15 -0700)
john1988 and Noam Rathaus reported that vti6_init_net() does not set the
netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).

Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel)
correctly set this flag during their fallback device initialization to
prevent them from being moved to another network namespace.

Fixes: 61220ab34948 ("vti6: Enable namespace changing")
Reported-by: Noam Rathaus <noamr@ssd-disclosure.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Steffen Klassert <steffen.klassert@secunet.com>
Reviewed-by: Nicolas Dichtel <nicolas.dichtel@6wind.com>
Link: https://patch.msgid.link/20260608155918.787644-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ipv6/ip6_vti.c

index df793c8bfffb0a26ea7f54933b88bccc9b1aa495..d2b74a6f2cf62dbb752d8842e1a4d33fc8392d41 100644 (file)
@@ -1159,6 +1159,7 @@ static int __net_init vti6_init_net(struct net *net)
                goto err_alloc_dev;
        dev_net_set(ip6n->fb_tnl_dev, net);
        ip6n->fb_tnl_dev->rtnl_link_ops = &vti6_link_ops;
+       ip6n->fb_tnl_dev->netns_immutable = true;
 
        err = vti6_fb_tnl_dev_init(ip6n->fb_tnl_dev);
        if (err < 0)