Re: [PATCH next v2] bonding: Display LACP info only to CAP_NET_ADMIN capable user

2015-06-18 Thread Mahesh Bandewar
>> >> Hmm... I would rather not send these fake attributes at all ? > > That would be my preference as well. Sorry if my lack of elaboration on > on my earlier email made this confusing. > > If there are values that should not be visible to non-root users, then > don't send them at all. Do not ju

Re: [PATCH next v2] bonding: Display LACP info only to CAP_NET_ADMIN capable user

2015-06-18 Thread Andy Gospodarek
On Thu, Jun 18, 2015 at 04:17:36AM -0700, Eric Dumazet wrote: > On Wed, 2015-06-17 at 17:59 -0700, Mahesh Bandewar wrote: > > Actor and Partner details can be accessed via proc-fs, sys-fs > > entries or netlink interface. These interfaces are world readable > > at this moment. The earlier patch-ser

Re: [PATCH next v2] bonding: Display LACP info only to CAP_NET_ADMIN capable user

2015-06-18 Thread Eric Dumazet
On Wed, 2015-06-17 at 17:59 -0700, Mahesh Bandewar wrote: > Actor and Partner details can be accessed via proc-fs, sys-fs > entries or netlink interface. These interfaces are world readable > at this moment. The earlier patch-series made the LACP communication > secure to avoid nuisance attack from