Thread (23 messages) 23 messages, 8 authors, 2016-02-12

Re: [PATCH 8/8] netfilter: implement xt_cgroup cgroup2 path match

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2015-12-14 19:38:03
Also in: cgroups, lkml, netfilter-devel

On Mon, Dec 07, 2015 at 05:38:55PM -0500, Tejun Heo wrote:
This patch implements xt_cgroup path match which matches cgroup2
membership of the associated socket.  The match is recursive and
invertible.
Applied, thanks.

I shared the same concerns as Florian regarding the large size of the
path field in iptables, but given that we expose the layout of our
internal representation there (which is bad in terms of
extensibility), the only solution that I can see is to artificially
limitate the size of that field, but that may break users depending on
the scenario.

Hopefully, we should be able to provide something better in nf_tables
to address this.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help