OpenVZ Forum


Home » Mailing lists » Devel » [RFC][patch 0/3] Network container subsystem - bind filtering
Re: Re: [RFC][patch 3/3] activate filtering for the bind [message #20005 is a reply to message #20000] Mon, 10 September 2007 18:11 Go to previous messageGo to previous message
serue is currently offline  serue
Messages: 750
Registered: February 2006
Senior Member
Quoting Paul Menage (menage@google.com):
> On 9/10/07, Serge E. Hallyn <serue@us.ibm.com> wrote:
> >
> > The only downside I see right now is what to do about a sendto() on a
> > udp socket that hasn't been bound.
> 
> Maybe have additional chains in the new iptable called "sendto" and
> "recvfrom" that are invoked for those operations on unbound datagram
> sockets?

Yup.

Perhaps the biggest upside of this approach is that it's providing
network functionality in a way that should be much more familiar to
network folks.  As opposed to using an lsm with a new vfs interface.

Is anyone working on this implementation, for comparison to the lsm
patch?

-serge
_______________________________________________
Containers mailing list
Containers@lists.linux-foundation.org
https://lists.linux-foundation.org/mailman/listinfo/containers
 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: Re: [PATCH] Hookup group-scheduler with task container infrastructure
Next Topic: [RFC] [PATCH 0/2] namespace enter through hijack
Goto Forum:
  


Current Time: Mon Oct 06 21:29:04 GMT 2025

Total time taken to generate the page: 0.25155 seconds