diff options
| author | Ana Rey <anarey@gmail.com> | 2014-11-03 12:10:50 -0500 |
|---|---|---|
| committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2014-11-09 10:21:22 -0500 |
| commit | ce674173e9f4ef7fd0dc04ea0773cdedfbf8e366 (patch) | |
| tree | 1ab3456f0effd56be2fc2fb25d2a7b02e012a716 /include/uapi/linux | |
| parent | c5a589cc3034d035e8490216a45abd3a3b3cd85e (diff) | |
netfilter: nft_meta: add cgroup support
This allows you to filter traffic by process control group (cgroup).
Signed-off-by: Ana Rey <anarey@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/uapi/linux')
| -rw-r--r-- | include/uapi/linux/netfilter/nf_tables.h | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/include/uapi/linux/netfilter/nf_tables.h b/include/uapi/linux/netfilter/nf_tables.h index 16f62a5cf04d..832bc46db78b 100644 --- a/include/uapi/linux/netfilter/nf_tables.h +++ b/include/uapi/linux/netfilter/nf_tables.h | |||
| @@ -579,6 +579,7 @@ enum nft_exthdr_attributes { | |||
| 579 | * @NFT_META_CPU: cpu id through smp_processor_id() | 579 | * @NFT_META_CPU: cpu id through smp_processor_id() |
| 580 | * @NFT_META_IIFGROUP: packet input interface group | 580 | * @NFT_META_IIFGROUP: packet input interface group |
| 581 | * @NFT_META_OIFGROUP: packet output interface group | 581 | * @NFT_META_OIFGROUP: packet output interface group |
| 582 | * @NFT_META_CGROUP: socket control group (skb->sk->sk_classid) | ||
| 582 | */ | 583 | */ |
| 583 | enum nft_meta_keys { | 584 | enum nft_meta_keys { |
| 584 | NFT_META_LEN, | 585 | NFT_META_LEN, |
| @@ -604,6 +605,7 @@ enum nft_meta_keys { | |||
| 604 | NFT_META_CPU, | 605 | NFT_META_CPU, |
| 605 | NFT_META_IIFGROUP, | 606 | NFT_META_IIFGROUP, |
| 606 | NFT_META_OIFGROUP, | 607 | NFT_META_OIFGROUP, |
| 608 | NFT_META_CGROUP, | ||
| 607 | }; | 609 | }; |
| 608 | 610 | ||
| 609 | /** | 611 | /** |
