• Pablo Neira Ayuso's avatar
    netfilter: nf_tables: add inet ingress support · d3519cb8
    Pablo Neira Ayuso authored
    This patch adds a new ingress hook for the inet family. The inet ingress
    hook emulates the IP receive path code, therefore, unclean packets are
    drop before walking over the ruleset in this basechain.
    
    This patch also introduces the nft_base_chain_netdev() helper function
    to check if this hook is bound to one or more devices (through the hook
    list infrastructure). This check allows to perform the same handling for
    the inet ingress as it would be a netdev ingress chain from the control
    plane.
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    d3519cb8
nf_tables.h 40.4 KB