[NETFILTER] nfnetlink: unconditionally require CAP_NET_ADMIN
authorHarald Welte <laforge@netfilter.org>
Mon, 14 Nov 2005 23:24:59 +0000 (15:24 -0800)
committerDavid S. Miller <davem@davemloft.net>
Mon, 14 Nov 2005 23:24:59 +0000 (15:24 -0800)
commit37d2e7a20d745035b600f1a6be56cbb9c7259419
treec76e0ba522d34c8b3021bf0f012632f7877f5281
parent3746a2b1402e7933c7f1eabdce384b8454dc2ef7
[NETFILTER] nfnetlink: unconditionally require CAP_NET_ADMIN

This patch unconditionally requires CAP_NET_ADMIN for all nfnetlink
messages.  It also removes the per-message cap_required field, since all
existing subsystems use CAP_NET_ADMIN for all their messages anyway.

Patrick McHardy owes me a beer if we ever need to re-introduce this.

Signed-off-by: Harald Welte <laforge@netfilter.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/linux/netfilter/nfnetlink.h
net/ipv4/netfilter/ip_conntrack_netlink.c
net/netfilter/nfnetlink.c
net/netfilter/nfnetlink_log.c
net/netfilter/nfnetlink_queue.c