Skip to content
  • Tejun Heo's avatar
    netfilter: implement xt_cgroup cgroup2 path match · c38c4597
    Tejun Heo authored
    
    
    This patch implements xt_cgroup path match which matches cgroup2
    membership of the associated socket.  The match is recursive and
    invertible.
    
    For rationales on introducing another cgroup based match, please refer
    to a preceding commit "sock, cgroup: add sock->sk_cgroup".
    
    v3: Folded into xt_cgroup as a new revision interface as suggested by
        Pablo.
    
    v2: Included linux/limits.h from xt_cgroup2.h for PATH_MAX.  Added
        explicit alignment to the priv field.  Both suggested by Jan.
    
    Signed-off-by: default avatarTejun Heo <tj@kernel.org>
    Cc: Daniel Borkmann <daniel@iogearbox.net>
    Cc: Daniel Wagner <daniel.wagner@bmw-carit.de>
    CC: Neil Horman <nhorman@tuxdriver.com>
    Cc: Jan Engelhardt <jengelh@inai.de>
    Cc: Pablo Neira Ayuso <pablo@netfilter.org>
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    c38c4597