[Devel,RHEL7,COMMIT] ve/sysctl/net: allow net.ipv4.vs.* in CT init userns

Submitted by Konstantin Khorenko on May 5, 2017, 3:03 p.m.

Details

Message ID 201705051503.v45F3gfG023749@finist_cl7.x64_64.work.ct
State New
Headers show

Patch hide | download patch | download mbox

diff --git a/net/netfilter/ipvs/ip_vs_ctl.c b/net/netfilter/ipvs/ip_vs_ctl.c
index 0d8330f..db4563d 100644
--- a/net/netfilter/ipvs/ip_vs_ctl.c
+++ b/net/netfilter/ipvs/ip_vs_ctl.c
@@ -3723,7 +3723,7 @@  static int __net_init ip_vs_control_net_init_sysctl(struct net *net)
 			return -ENOMEM;
 
 		/* Don't export sysctls to unprivileged users */
-		if (net->user_ns != &init_user_ns)
+		if (ve_net_hide_sysctl(net))
 			tbl[0].procname = NULL;
 	} else
 		tbl = vs_vars;