Skip to content
  • Pablo Neira Ayuso's avatar
    netfilter: nf_tables: add nft_dup expression · d877f071
    Pablo Neira Ayuso authored
    
    
    This new expression uses the nf_dup engine to clone packets to a given gateway.
    Unlike xt_TEE, we use an index to indicate output interface which should be
    fine at this stage.
    
    Moreover, change to the preemtion-safe this_cpu_read(nf_skb_duplicated) from
    nf_dup_ipv{4,6} to silence a lockdep splat.
    
    Based on the original tee expression from Arturo Borrero Gonzalez, although
    this patch has diverted quite a bit from this initial effort due to the
    change to support maps.
    
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    d877f071