• Pablo Neira Ayuso's avatar
    netfilter: nf_tables: add optional user data area to rules · 0768b3b3
    Pablo Neira Ayuso authored
    This allows us to store user comment strings, but it could be also
    used to store any kind of information that the user application needs
    to link to the rule.
    
    Scratch 8 bits for the new ulen field that indicates the length the
    user data area. 4 bits from the handle (so it's 42 bits long, according
    to Patrick, it would last 139 years with 1000 new rules per second)
    and 4 bits from dlen (so the expression data area is 4K, which seems
    sufficient by now even considering the compatibility layer).
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    Acked-by: default avatarPatrick McHardy <kaber@trash.net>
    0768b3b3
nf_tables.h 14.2 KB