Message ID | 20210412042453.32168-1-Jonathon.Reinhart@gmail.com (mailing list archive) |
---|---|
Headers | show |
Series | Ensuring net sysctl isolation | expand |
Hello: This series was applied to netdev/net-next.git (refs/heads/master): On Mon, 12 Apr 2021 00:24:51 -0400 you wrote: > This patchset is the result of an audit of /proc/sys/net to prove that > it is safe to be mouted read-write in a container when a net namespace > is in use. See [1]. > > The first commit adds code to detect sysctls which are not netns-safe, > and can "leak" changes to other net namespaces. > > [...] Here is the summary with links: - [net-next,1/2] net: Ensure net namespace isolation of sysctls https://git.kernel.org/netdev/net-next/c/31c4d2f160eb - [net-next,2/2] netfilter: conntrack: Make global sysctls readonly in non-init netns https://git.kernel.org/netdev/net-next/c/2671fa4dc010 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html