[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Line.LNX.4.64.0707201124070.7319@d.namei>
Date: Fri, 20 Jul 2007 11:28:57 -0400 (EDT)
From: James Morris <jmorris@...ei.org>
To: Tetsuo Handa <from-netdev@...ove.SAKURA.ne.jp>
cc: shemminger@...ux-foundation.org, netdev@...r.kernel.org,
linux-security-module@...r.kernel.org,
Patrick McHardy <kaber@...sh.net>
Subject: Re: [PATCH 1/1] Allow LSM to use IP address/port number.
On Sat, 21 Jul 2007, Tetsuo Handa wrote:
> I can't use netfilter infrastructure because
> it is too early to know who the recipant process of the packet is.
I think the way forward on this is to re-visit the idea of providing a
proper solution for the incoming packet/user match problem.
I posted one possible solution a couple of years ago (skfilter):
http://lwn.net/Articles/157137/
I think there has been some recent discussion by netfilter developers
about this issue, so perhaps you could talk to them (cd'd Patrick).
- James
--
James Morris
<jmorris@...ei.org>
-
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists