Blame view
net/netfilter/xt_cgroup.c
1.83 KB
82a37132f
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 |
/* * Xtables module to match the process control group. * * Might be used to implement individual "per-application" firewall * policies in contrast to global policies based on control groups. * Matching is based upon processes tagged to net_cls' classid marker. * * (C) 2013 Daniel Borkmann <dborkman@redhat.com> * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License version 2 as * published by the Free Software Foundation. */ #include <linux/skbuff.h> #include <linux/module.h> #include <linux/netfilter/x_tables.h> #include <linux/netfilter/xt_cgroup.h> #include <net/sock.h> MODULE_LICENSE("GPL"); MODULE_AUTHOR("Daniel Borkmann <dborkman@redhat.com>"); MODULE_DESCRIPTION("Xtables: process control group matching"); MODULE_ALIAS("ipt_cgroup"); MODULE_ALIAS("ip6t_cgroup"); static int cgroup_mt_check(const struct xt_mtchk_param *par) { struct xt_cgroup_info *info = par->matchinfo; if (info->invert & ~1) return -EINVAL; |
caa8ad94e
|
33 |
return 0; |
82a37132f
|
34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 |
} static bool cgroup_mt(const struct sk_buff *skb, struct xt_action_param *par) { const struct xt_cgroup_info *info = par->matchinfo; if (skb->sk == NULL) return false; return (info->id == skb->sk->sk_classid) ^ info->invert; } static struct xt_match cgroup_mt_reg __read_mostly = { .name = "cgroup", .revision = 0, .family = NFPROTO_UNSPEC, .checkentry = cgroup_mt_check, .match = cgroup_mt, .matchsize = sizeof(struct xt_cgroup_info), .me = THIS_MODULE, .hooks = (1 << NF_INET_LOCAL_OUT) | |
a00e76349
|
56 57 |
(1 << NF_INET_POST_ROUTING) | (1 << NF_INET_LOCAL_IN), |
82a37132f
|
58 59 60 61 62 63 64 65 66 67 68 69 70 71 |
}; static int __init cgroup_mt_init(void) { return xt_register_match(&cgroup_mt_reg); } static void __exit cgroup_mt_exit(void) { xt_unregister_match(&cgroup_mt_reg); } module_init(cgroup_mt_init); module_exit(cgroup_mt_exit); |