[Devel] Re: unlock iptables in netns
Patrick McHardy
kaber at trash.net
Mon Jun 16 03:26:03 PDT 2008
Patrick McHardy wrote:
> Alexey Dobriyan wrote:
>> Hi,
>>
>> Den basically banned iptables in netns via this patch
>>
>> --- a/net/netfilter/core.c
>> +++ b/net/netfilter/core.c
>> ...
>> , however, at least some of netfilter pieces are ready for usage in netns
>> and it would be nice to unlock them before release.
>>
>> If I'm deciphering chengelog correctly it's all about code which does
>> nf_register_hook{,s} but not netns-ready itself:
>>
>> br_netfilter.c
>> iptable_mangle (via ip_route_me_harder)
>> conntracking (both IPv4 and IPv6)
>> NAT
>> ...
>> Patch above can be applied and we can mark above list as "depends
>> !NET_NS"
>> and move on.
>>
>> Comments? Den, was there something else you're afraid of?
>
>
> That might result in some bad surprises for people how have already
> turned on NET_NS. I'd prefer a way that doesn't potentially disable
> half the netfilter options in existing configs.
By the way, is there already work done for conntrack/NAT namespace
support? I have this patch that uses marks for something very similar
that should be easy to adjust.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: x
URL: <http://lists.openvz.org/pipermail/devel/attachments/20080616/fba22f17/attachment-0001.ksh>
More information about the Devel
mailing list