From mboxrd@z Thu Jan 1 00:00:00 1970 From: pawa Subject: Re: tag process's future sockets for iptables rules? Date: Sat, 22 Oct 2011 23:28:34 +0000 Message-ID: <1RHkzU-0005iK-Tn@internal.tormail.net> References: <1RHeWb-0000Qb-4M@internal.tormail.net> Mime-Version: 1.0 Return-path: DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=tormail.net; s=tm; h=Message-Id:X-TorMail-User:In-Reply-To:Content-Type:MIME-Version:References:Subject:To:From:Date; bh=1nV8LaC/slN3wm9kvQ0UykKOIXoCSf2W2hdqcRAge4U=; b=XbheJGz9znZBS6W2BFdGND+9yf/Y7MzQ2ndFCXvOqfpaYviE+Ssch4GTjUay3oDGCMeoXZcQ1see7zfhT3HtfBUn967GXebnKRNtIXbXYjIY9xsfiNJ3UiEdO9Gqu5KtlcCBwplwxwd7ChCqPJ4csvTUbL9KnjK0Q1uV510pW5g=; Content-Disposition: inline In-Reply-To: Sender: netfilter-owner@vger.kernel.org List-ID: Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: netfilter@vger.kernel.org > >| netfilter_add_tag("public-addresses-proxied-via-tor"); > >| netfilter_add_tag("internal-addresses-directly"); > >| netfilter_remove_tag("proxy-dns"); > >| execlp("wget", ...); > > A socket option, SO_MARK, for use with setsockopt/getsockopt. but setsockopt is per socket. i'm looking for something that is per process (and inherited by children - in the example, wget). this is to replace what i do at the moment, namely | setgid(123); | execlp("wget", ...); and # iptables ... -m owner --gid-owner 123 ...