netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH nf-next 0/3] netfilter: nftables: add set support for conntrack labels
@ 2015-12-07 12:05 Florian Westphal
  2015-12-07 12:05 ` [PATCH nf-next 1/3] netfilter: connlabels: move helpers to xt_connlabel Florian Westphal
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Florian Westphal @ 2015-12-07 12:05 UTC (permalink / raw)
  To: netfilter-devel

make "add rule filter input ct label set ct label | bar" work.

First patch is a cleanup and moves xt specific code to xt_connlabel.

Second patch is a fix to the clabel replace function to not emit
an event in case old and new are the same (this isn't a problem
for xtables since it doesn't use nf_connlabels_replace).

Last patch adds nft_ct set support.

Let me know if you spot any problems with this approach.
I'm especially interested in the userspace side, see patch
#3 for example.

 include/net/netfilter/nf_conntrack_labels.h |    3 -
 net/netfilter/nf_conntrack_labels.c         |   50 +++++-----------------------
 net/netfilter/nft_ct.c                      |   31 +++++++++++++++++
 net/netfilter/xt_connlabel.c                |   38 ++++++++++++++++++++-
 4 files changed, 77 insertions(+), 45 deletions(-)


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2015-12-07 12:05 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-12-07 12:05 [PATCH nf-next 0/3] netfilter: nftables: add set support for conntrack labels Florian Westphal
2015-12-07 12:05 ` [PATCH nf-next 1/3] netfilter: connlabels: move helpers to xt_connlabel Florian Westphal
2015-12-07 12:05 ` [PATCH nf-next 2/3] netfilter: labels: don't emit ct event if labels are unchanged Florian Westphal
2015-12-07 12:05 ` [PATCH nf-next 3/3] netfilter: nftables: add connlabel set support Florian Westphal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).