Re: [PATCH next v0] bonding: Display LACP info only to CAP_SYS_ADMIN capable user

2015-06-12 Thread Mahesh Bandewar
On Thu, Jun 11, 2015 at 3:22 PM, David Miller wrote: > > From: Mahesh Bandewar > Date: Wed, 10 Jun 2015 17:19:56 -0700 > > > Actor and Partner details can be accessed via proc-fs and sys-fs > > entries. These interfaces are world readable at this moment. The > > earlier patch-series made the LACP

Re: [PATCH next v0] bonding: Display LACP info only to CAP_SYS_ADMIN capable user

2015-06-11 Thread David Miller
From: Mahesh Bandewar Date: Wed, 10 Jun 2015 17:19:56 -0700 > Actor and Partner details can be accessed via proc-fs and sys-fs > entries. These interfaces are world readable at this moment. The > earlier patch-series made the LACP communication secure to avoid > nuisance attack from within the sa

Re: [PATCH next v0] bonding: Display LACP info only to CAP_SYS_ADMIN capable user

2015-06-11 Thread Stephen Hemminger
On Wed, 10 Jun 2015 17:19:56 -0700 Mahesh Bandewar wrote: > Actor and Partner details can be accessed via proc-fs and sys-fs > entries. These interfaces are world readable at this moment. The > earlier patch-series made the LACP communication secure to avoid > nuisance attack from within the same

[PATCH next v0] bonding: Display LACP info only to CAP_SYS_ADMIN capable user

2015-06-10 Thread Mahesh Bandewar
Actor and Partner details can be accessed via proc-fs and sys-fs entries. These interfaces are world readable at this moment. The earlier patch-series made the LACP communication secure to avoid nuisance attack from within the same L2 domain but it did not prevent "someone unprivileged" looking at