netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] NFQUEUE v2 target with 'queue bypass' support
@ 2010-12-26 23:58 Florian Westphal
  2010-12-26 23:58 ` [PATCH 1/6] netfilter: kconfig: NFQUEUE is useless without NETFILTER_NETLINK_QUEUE Florian Westphal
                   ` (5 more replies)
  0 siblings, 6 replies; 23+ messages in thread
From: Florian Westphal @ 2010-12-26 23:58 UTC (permalink / raw)
  To: netfilter-devel

Following patch series (for net-next) adds a NFQUEUE v2 target revision
that introduces a "--queue-bypass" flag.

If the flag is used with a -j NFQUEUE rule, then NFQUEUE will behave
like ACCEPT instead of DROP iff no program has opened the queue.

I will send the userspace patch for iptables in a couple of days.

The patch series is also available via git, but beware:
the tree is based on net-next-2.6 and NOT nf-next, because the former
includes Eric Paris' selinux netfilter changes which would
cause merge conflicts with these patches.

The following changes since commit 041110a439e21cd40709ead4ffbfa8034619ad77:

  Merge branch 'master' of master.kernel.org:/pub/scm/linux/kernel/git/jkirsher/net-next-2.6 (2010-12-25 19:20:38 -0800)

are available in the git repository at:

  git://git.breakpoint.cc/fw/net-next-2.6.git nfq_bypass

Florian Westphal (6):
      netfilter: kconfig: NFQUEUE is useless without NETFILTER_NETLINK_QUEUE
      netfilter: nfnetlink_queue: return error number to caller
      netfilter: nfnetlink_queue: do not free skb on error
      netfilter: reduce NF_VERDICT_MASK to 0xff
      netfilter: allow NFQUEUE bypass if no listener is available
      netfilter: do not omit re-route check on NF_QUEUE verdict

 include/linux/netfilter.h            |   21 ++++++++---
 include/linux/netfilter/xt_NFQUEUE.h |    6 +++
 net/ipv4/netfilter/iptable_mangle.c  |    2 +-
 net/netfilter/Kconfig                |    1 +
 net/netfilter/core.c                 |   14 +++++--
 net/netfilter/nf_queue.c             |   66 +++++++++++++++++++++------------
 net/netfilter/nfnetlink_queue.c      |   22 +++++++----
 net/netfilter/xt_NFQUEUE.c           |   28 +++++++++++++--
 8 files changed, 115 insertions(+), 45 deletions(-)


^ permalink raw reply	[flat|nested] 23+ messages in thread
* [PATCH v2] NFQUEUE v2 target with 'queue bypass' support
@ 2011-01-16 13:19 Florian Westphal
  2011-01-16 13:19 ` [PATCH 3/6] netfilter: nfnetlink_queue: do not free skb on error Florian Westphal
  0 siblings, 1 reply; 23+ messages in thread
From: Florian Westphal @ 2011-01-16 13:19 UTC (permalink / raw)
  To: netfilter-devel

This is V2 of the NFQUEUEv2 target revision, adding support for accepting
packets in case the userspace listener is not available.
This fixes issues pointed out by Pablo in his review.

See individual patches for changes vs. V1.
Patch to iptables userspace follows in a couple of minutes.

These changes are also available via git pull:

The following changes since commit d862a6622e9db508d4b28cc7c5bc28bd548cc24e:

  netfilter: nf_conntrack: use is_vmalloc_addr() (2011-01-14 15:45:56 +0100)

are available in the git repository at:
  git://git.breakpoint.cc/fw/nf-next-2.6.git nfq_bypass_v2

Florian Westphal (6):
      netfilter: kconfig: NFQUEUE is useless without NETFILTER_NETLINK_QUEUE
      netfilter: nfnetlink_queue: return error number to caller
      netfilter: nfnetlink_queue: do not free skb on error
      netfilter: reduce NF_VERDICT_MASK to 0xff
      netfilter: allow NFQUEUE bypass if no listener is available
      netfilter: do not omit re-route check on NF_QUEUE verdict

 include/linux/netfilter.h            |   21 ++++++++---
 include/linux/netfilter/xt_NFQUEUE.h |    6 +++
 net/ipv4/netfilter/iptable_mangle.c  |    2 +-
 net/netfilter/Kconfig                |    1 +
 net/netfilter/core.c                 |   16 ++++++--
 net/netfilter/nf_queue.c             |   64 ++++++++++++++++++++++++----------
 net/netfilter/nfnetlink_queue.c      |   22 +++++++----
 net/netfilter/xt_NFQUEUE.c           |   28 +++++++++++++--
 8 files changed, 120 insertions(+), 40 deletions(-)

^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2011-01-18 14:29 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-12-26 23:58 [PATCH] NFQUEUE v2 target with 'queue bypass' support Florian Westphal
2010-12-26 23:58 ` [PATCH 1/6] netfilter: kconfig: NFQUEUE is useless without NETFILTER_NETLINK_QUEUE Florian Westphal
2010-12-27  8:41   ` Jan Engelhardt
2010-12-27  8:47     ` Michał Mirosław
2010-12-26 23:58 ` [PATCH 2/6] netfilter: nfnetlink_queue: return error number to caller Florian Westphal
2011-01-12 18:56   ` Pablo Neira Ayuso
2011-01-12 20:49     ` Florian Westphal
2011-01-12 21:59       ` Pablo Neira Ayuso
2011-01-13  0:14         ` Florian Westphal
2010-12-26 23:58 ` [PATCH 3/6] netfilter: nfnetlink_queue: do not free skb on error Florian Westphal
2011-01-12 19:01   ` Pablo Neira Ayuso
2011-01-12 20:50     ` Florian Westphal
2010-12-26 23:58 ` [PATCH 4/6] netfilter: reduce NF_VERDICT_MASK to 0xff Florian Westphal
2011-01-12 19:02   ` Pablo Neira Ayuso
2011-01-12 20:52     ` Florian Westphal
2011-01-14 14:05       ` Patrick McHardy
2011-01-15 14:29         ` Pablo Neira Ayuso
2011-01-15 14:33           ` Patrick McHardy
2010-12-26 23:58 ` [PATCH 5/6] netfilter: allow NFQUEUE bypass if no listener is available Florian Westphal
2011-01-12 19:03   ` Pablo Neira Ayuso
2010-12-26 23:58 ` [PATCH 6/6] netfilter: do not omit re-route check on NF_QUEUE verdict Florian Westphal
  -- strict thread matches above, loose matches on Subject: below --
2011-01-16 13:19 [PATCH v2] NFQUEUE v2 target with 'queue bypass' support Florian Westphal
2011-01-16 13:19 ` [PATCH 3/6] netfilter: nfnetlink_queue: do not free skb on error Florian Westphal
2011-01-18 14:29   ` Patrick McHardy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).