Thread (20 messages) 20 messages, 5 authors, 2015-11-20

Re: [PATCHSET v2] netfilter, cgroup: implement xt_cgroup2 match

From: Pablo Neira Ayuso <hidden>
Date: 2015-11-20 19:57:45
Also in: cgroups, lkml, netfilter-devel

On Fri, Nov 20, 2015 at 08:56:25PM +0100, Pablo Neira Ayuso wrote:
Regarding #7, I have a couple two concerns:

1) cgroup currently doesn't work the way users expect, ie. to perform any
   reasonable firewalling. Since this relies on early demux, only a
   limited number of sockets get access to the cgroup info.
Ops sorry, I forgot to indicate that I'm refering to the INPUT chain.
2) We have traditionally rejected match2 and target2 extensions. I
   guess you can accomodate the new cgroup code through the revision
   iptables infrastructure, so we still use the cgroup match.

Let me know, thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help