Thread (4 messages) 4 messages, 2 authors, 2018-09-28

[PATCH v3 1/2] netfilter: nf_tables: add SECMARK support

From: pablo@netfilter.org (Pablo Neira Ayuso)
Date: 2018-09-28 09:01:18
Also in: lkml, netdev, netfilter-devel, selinux

On Sun, Sep 23, 2018 at 08:26:15PM +0200, Christian G?ttsche wrote:
Add the ability to set the security context of packets within the nf_tables framework.
Add a nft_object for holding security contexts in the kernel and manipulating packets on the wire.

Convert the security context strings at rule addition time to security identifiers.
This is the same behavior like in xt_SECMARK and offers better performance than computing it per packet.

Set the maximum security context length to 256.
Applied, thanks Christian.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help