From: Herve Eychenne <rv@wallfire.org>
To: Patrick McHardy <kaber@trash.net>
Cc: netfilter-devel@lists.netfilter.org,
Sebastien Tricaud <sebastien.tricaud@wengo.fr>
Subject: Re: Knowing tables change
Date: Thu, 16 Mar 2006 11:12:26 +0100 [thread overview]
Message-ID: <20060316101226.GO25252@eychenne.org> (raw)
In-Reply-To: <441587CF.4050203@trash.net>
On Mon, Mar 13, 2006 at 03:55:11PM +0100, Patrick McHardy wrote:
> Sebastien Tricaud wrote:
> > Hi folks,
> >
> > I would like to know if there is a way to watch for tables alteration.
> >
> > I am sure there is a better way than doing "iptables -t table -L" loop
> > and compare with previously stored data.
> watch -n 1 -d iptables -vxnL :)
> > When I look over Internet for possible answers, I can find something
> > that would do the job. It seems libpkttnetlink is for this purpose.
> > However no developments are latter than 2002. Is it a working stuff and
> > nothing has to be improved anymore ?
> >
> > At a lower level, I can see libnfnetlink is the low level library I can
> > also use for it: there is the following quote -> "provides
> > open/close/receive functions only to be used by other libraries
> > libctnetlink/libpkttnetlink".
> There are no notifications for ruleset updates currently, since
> ruleset exchange between kernel and userspace isn't built on
> netlink and happens as one atomic operation, so the kernel
> doesn't know which rules are new.
Does listing the rules imply some locking? I guess it can be a costly
operation if the ruleset is big...
It would at least be nice to send a "signal" (via netlink) when the
ruleset is changed, so that third party applications can figure out
the changes themselves only when needed (without having to do regular
active polls).
Herve
--
_
(°= Hervé Eychenne
//)
v_/_ WallFire project: http://www.wallfire.org/
prev parent reply other threads:[~2006-03-16 10:12 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-03-13 11:47 Knowing tables change Sebastien Tricaud
2006-03-13 14:55 ` Patrick McHardy
2006-03-16 10:12 ` Herve Eychenne [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060316101226.GO25252@eychenne.org \
--to=rv@wallfire.org \
--cc=kaber@trash.net \
--cc=netfilter-devel@lists.netfilter.org \
--cc=sebastien.tricaud@wengo.fr \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.