From mboxrd@z Thu Jan 1 00:00:00 1970 From: pablo@netfilter.org (Pablo Neira Ayuso) Date: Fri, 28 Sep 2018 11:01:11 +0200 Subject: [PATCH v3 1/2] netfilter: nf_tables: add SECMARK support In-Reply-To: <20180923182616.11398-1-cgzones@googlemail.com> References: <20180923182616.11398-1-cgzones@googlemail.com> Message-ID: <20180928090111.7h2rj5vbf5l2dzcy@salvia> To: linux-security-module@vger.kernel.org List-Id: linux-security-module.vger.kernel.org On Sun, Sep 23, 2018 at 08:26:15PM +0200, Christian G?ttsche wrote: > Add the ability to set the security context of packets within the nf_tables framework. > Add a nft_object for holding security contexts in the kernel and manipulating packets on the wire. > > Convert the security context strings at rule addition time to security identifiers. > This is the same behavior like in xt_SECMARK and offers better performance than computing it per packet. > > Set the maximum security context length to 256. Applied, thanks Christian.