31 Oct, 2016
1 commit
-
The NFTA_DUP_SREG_DEV attribute is not a must option, so we should use it
in routing lookup only when the user specify it.Fixes: d877f07112f1 ("netfilter: nf_tables: add nft_dup expression")
Signed-off-by: Liping Zhang
Signed-off-by: Pablo Neira Ayuso
19 Sep, 2015
2 commits
-
This allows them to stop guessing the network namespace with pick_net.
Signed-off-by: "Eric W. Biederman"
Signed-off-by: Pablo Neira Ayuso -
- Add nft_pktinfo.pf to replace ops->pf
- Add nft_pktinfo.hook to replace ops->hooknumThis simplifies the code, makes it more readable, and likely reduces
cache line misses. Maintainability is enhanced as the details of
nft_hook_ops are of no concern to the recpients of nft_pktinfo.Signed-off-by: "Eric W. Biederman"
Signed-off-by: Pablo Neira Ayuso
07 Aug, 2015
1 commit
-
This new expression uses the nf_dup engine to clone packets to a given gateway.
Unlike xt_TEE, we use an index to indicate output interface which should be
fine at this stage.Moreover, change to the preemtion-safe this_cpu_read(nf_skb_duplicated) from
nf_dup_ipv{4,6} to silence a lockdep splat.Based on the original tee expression from Arturo Borrero Gonzalez, although
this patch has diverted quite a bit from this initial effort due to the
change to support maps.Signed-off-by: Pablo Neira Ayuso