Re: [PATCHSET v2] netfilter, cgroup: implement xt_cgroup2 match
From: Pablo Neira Ayuso <hidden>
Date: 2015-11-20 19:57:45
Also in:
cgroups, lkml, netfilter-devel
From: Pablo Neira Ayuso <hidden>
Date: 2015-11-20 19:57:45
Also in:
cgroups, lkml, netfilter-devel
On Fri, Nov 20, 2015 at 08:56:25PM +0100, Pablo Neira Ayuso wrote:
Regarding #7, I have a couple two concerns: 1) cgroup currently doesn't work the way users expect, ie. to perform any reasonable firewalling. Since this relies on early demux, only a limited number of sockets get access to the cgroup info.
Ops sorry, I forgot to indicate that I'm refering to the INPUT chain.
2) We have traditionally rejected match2 and target2 extensions. I guess you can accomodate the new cgroup code through the revision iptables infrastructure, so we still use the cgroup match. Let me know, thanks.