netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Gao feng <gaofeng@cn.fujitsu.com>
To: netfilter-devel@vger.kernel.org
Cc: containers@lists.linux-foundation.org, pablo@netfilter.org,
	ebiederm@xmission.com, netdev@vger.kernel.org, lve@guap.ru,
	Gao feng <gaofeng@cn.fujitsu.com>
Subject: [PATCH 03/10] netfilter: ebt_log: add net namespace support for ebt_log
Date: Thu, 7 Feb 2013 15:49:43 +0800	[thread overview]
Message-ID: <1360223390-15589-3-git-send-email-gaofeng@cn.fujitsu.com> (raw)
In-Reply-To: <1360223390-15589-1-git-send-email-gaofeng@cn.fujitsu.com>

Add pernet_operations for ebt_log, in pernet_ops,
we call nf_log_set/unset to set/unset nf_loggers
of per net.

Because the syslog ns has not been implemented,
we don't want the container DOS the host's syslog.
so only enable ebt_log in init_net and wait for
syslog ns.

Signed-off-by: Gao feng <gaofeng@cn.fujitsu.com>
---
 net/bridge/netfilter/ebt_log.c | 24 +++++++++++++++++++++++-
 1 file changed, 23 insertions(+), 1 deletion(-)

diff --git a/net/bridge/netfilter/ebt_log.c b/net/bridge/netfilter/ebt_log.c
index 1d397ac..a654240 100644
--- a/net/bridge/netfilter/ebt_log.c
+++ b/net/bridge/netfilter/ebt_log.c
@@ -78,6 +78,10 @@ ebt_log_packet(u_int8_t pf, unsigned int hooknum,
    const char *prefix)
 {
 	unsigned int bitmask;
+	struct net *net = dev_net((in != NULL) ? in : out);
+
+	if (!net_eq(net, &init_net))
+		return;
 
 	spin_lock_bh(&ebt_log_lock);
 	printk(KERN_SOH "%c%s IN=%s OUT=%s MAC source = %pM MAC dest = %pM proto = 0x%04x",
@@ -207,6 +211,22 @@ static struct nf_logger ebt_log_logger __read_mostly = {
 	.me		= THIS_MODULE,
 };
 
+static int __net_init ebt_log_net_init(struct net *net)
+{
+	nf_log_set(net, NFPROTO_BRIDGE, &ebt_log_logger);
+	return 0;
+}
+
+static void __net_exit ebt_log_net_fini(struct net *net)
+{
+	nf_log_unset(net, &ebt_log_logger);
+}
+
+static struct pernet_operations ebt_log_net_ops = {
+	.init = ebt_log_net_init,
+	.exit = ebt_log_net_fini,
+};
+
 static int __init ebt_log_init(void)
 {
 	int ret;
@@ -214,12 +234,14 @@ static int __init ebt_log_init(void)
 	ret = xt_register_target(&ebt_log_tg_reg);
 	if (ret < 0)
 		return ret;
+
 	nf_log_register(NFPROTO_BRIDGE, &ebt_log_logger);
-	return 0;
+	return register_pernet_subsys(&ebt_log_net_ops);
 }
 
 static void __exit ebt_log_fini(void)
 {
+	unregister_pernet_subsys(&ebt_log_net_ops);
 	nf_log_unregister(&ebt_log_logger);
 	xt_unregister_target(&ebt_log_tg_reg);
 }
-- 
1.7.11.7

  reply	other threads:[~2013-02-07  7:49 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-02-07  7:49 [PATCH 01/10] netfilter: make /proc/net/netfilter pernet Gao feng
2013-02-07  7:49 ` Gao feng [this message]
     [not found] ` <1360223390-15589-1-git-send-email-gaofeng-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2013-02-07  7:49   ` [PATCH 02/10] netfilter: nf_log: prepar net namespace support for nf_log Gao feng
     [not found]     ` <1360223390-15589-2-git-send-email-gaofeng-BthXqXjhjHXQFUHtdCDX3A@public.gmane.org>
2013-02-07 18:39       ` Pablo Neira Ayuso
2013-11-05 14:14       ` Arnaldo Carvalho de Melo
2013-11-06  2:00         ` Gao feng
2013-02-07  7:49   ` [PATCH 04/10] netfilter: xt_LOG: add net namespace support for xt_LOG Gao feng
2013-02-07  7:49   ` [PATCH 05/10] netfilter: ebt_ulog: add net namesapce support for ebt_ulog Gao feng
2013-02-07  7:49 ` [PATCH 06/10] netfilter: ipt_ulog: add net namespace support for ipt_ulog Gao feng
2013-02-07  7:57   ` Gao feng
2013-02-07  7:49 ` [PATCH 07/10] netfilter: nfnetlink_log: add net namespace support for nfnetlink_log Gao feng
2013-02-07  7:49 ` [PATCH 08/10] netfilter: nf_log: enable nflog in un-init net namespace Gao feng
2013-02-07  7:49 ` [PATCH 09/10] netfilter: nfnetlink_queue: add net namespace support for nfnetlink_queue Gao feng
2013-02-07  7:49 ` [PATCH 10/10] netfilter: remove useless variable proc_net_netfilter Gao feng
2013-02-07 18:33 ` [PATCH 01/10] netfilter: make /proc/net/netfilter pernet Pablo Neira Ayuso
2013-02-20  6:36   ` Gao feng
2013-02-20 23:13     ` Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1360223390-15589-3-git-send-email-gaofeng@cn.fujitsu.com \
    --to=gaofeng@cn.fujitsu.com \
    --cc=containers@lists.linux-foundation.org \
    --cc=ebiederm@xmission.com \
    --cc=lve@guap.ru \
    --cc=netdev@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pablo@netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).