Re: [Q] Unable to load SCHED_CLS/SCHED_ACT bpf programs from outside init_user_ns

2018-02-10 Thread Shmulik Ladkani
Hi, On Sat, 10 Feb 2018 14:08:58 +0100 Daniel Borkmann wrote: > Hi Shmulik, > > On 02/10/2018 08:46 AM, Shmulik Ladkani wrote: > > Hi, > > > > Apparently one cannot use TC cls_bpf/act_bpf if running from a user ns > > other than the init_user_ns, as bpf_prog_load does not permit loading > > th

Re: [Q] Unable to load SCHED_CLS/SCHED_ACT bpf programs from outside init_user_ns

2018-02-10 Thread Daniel Borkmann
Hi Shmulik, On 02/10/2018 08:46 AM, Shmulik Ladkani wrote: > Hi, > > Apparently one cannot use TC cls_bpf/act_bpf if running from a user ns > other than the init_user_ns, as bpf_prog_load does not permit loading > these type of progs, snip: > > if (type != BPF_PROG_TYPE_SOCKET_FILTER &&

[Q] Unable to load SCHED_CLS/SCHED_ACT bpf programs from outside init_user_ns

2018-02-09 Thread Shmulik Ladkani
Hi, Apparently one cannot use TC cls_bpf/act_bpf if running from a user ns other than the init_user_ns, as bpf_prog_load does not permit loading these type of progs, snip: if (type != BPF_PROG_TYPE_SOCKET_FILTER && type != BPF_PROG_TYPE_CGROUP_SKB && !capable(CAP_S