[NETFILTER]: x_tables: per-netns xt_tables
authorAlexey Dobriyan <adobriyan@sw.ru>
Thu, 31 Jan 2008 12:02:13 +0000 (04:02 -0800)
committerDavid S. Miller <davem@davemloft.net>
Fri, 1 Feb 2008 03:27:35 +0000 (19:27 -0800)
commit8d870052079d255917ec4f8431f5ec102707b7af
tree77ab4f07ef4980d179c4e47d3a6e034c055f9bdf
parenta98da11d88dbec1d5cebe2c6dbe9939ed8d13f69
[NETFILTER]: x_tables: per-netns xt_tables

In fact all we want is per-netns set of rules, however doing that will
unnecessary complicate routines such as ipt_hook()/ipt_do_table, so
make full xt_table array per-netns.

Every user stubbed with init_net for a while.

Signed-off-by: Alexey Dobriyan <adobriyan@sw.ru>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/linux/netfilter/x_tables.h
include/net/net_namespace.h
include/net/netns/x_tables.h [new file with mode: 0644]
net/ipv4/netfilter/arp_tables.c
net/ipv4/netfilter/ip_tables.c
net/ipv6/netfilter/ip6_tables.c
net/netfilter/x_tables.c