<feed xmlns='http://www.w3.org/2005/Atom'>
<title>android_external_iptables, branch stable/cm-13.0-ZNH2K</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.
</subtitle>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/'/>
<entry>
<title>Merge tag 'android-6.0.0_r26' into cm-13.0</title>
<updated>2015-11-05T00:42:15+00:00</updated>
<author>
<name>Ricardo Cerqueira</name>
<email>ricardo@cyngn.com</email>
</author>
<published>2015-11-05T00:42:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=e075a20fc1379d617d1e4e7b064ea1d50eac10d6'/>
<id>e075a20fc1379d617d1e4e7b064ea1d50eac10d6</id>
<content type='text'>
Android 6.0.0 release 26
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Android 6.0.0 release 26
</pre>
</div>
</content>
</entry>
<entry>
<title>extensions: libxt_socket: add --restore-skmark option</title>
<updated>2015-10-06T09:30:27+00:00</updated>
<author>
<name>Harout Hedeshian</name>
<email>harouth@codeaurora.org</email>
</author>
<published>2015-08-22T01:23:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=ac06e5223ab5ed1462d6c8346b2eaba207f449b7'/>
<id>ac06e5223ab5ed1462d6c8346b2eaba207f449b7</id>
<content type='text'>
xt_socket is useful for matching sockets with IP_TRANSPARENT and
taking some action on the matching packets. However, it lacks the
ability to match only a small subset of transparent sockets.

Suppose there are 2 applications, each with its own set of transparent
sockets. The first application wants all matching packets dropped,
while the second application wants them forwarded somewhere else.

Add the ability to retore the skb-&gt;mark from the sk_mark. The mark
is only restored if a matching socket is found and the transparent /
nowildcard conditions are satisfied.

Now the 2 hypothetical applications can differentiate their sockets
based on a mark value set with SO_MARK.

iptables -t mangle -I PREROUTING -m socket --transparent \
                                           --restore-skmark -j action
iptables -t mangle -A action -m mark --mark 10 -j action2
iptables -t mangle -A action -m mark --mark 11 -j action3

Change-Id: I962e87f32c241cb8d056dfd62f296fa312b05162
Signed-off-by: Harout Hedeshian &lt;harouth@codeaurora.org&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
xt_socket is useful for matching sockets with IP_TRANSPARENT and
taking some action on the matching packets. However, it lacks the
ability to match only a small subset of transparent sockets.

Suppose there are 2 applications, each with its own set of transparent
sockets. The first application wants all matching packets dropped,
while the second application wants them forwarded somewhere else.

Add the ability to retore the skb-&gt;mark from the sk_mark. The mark
is only restored if a matching socket is found and the transparent /
nowildcard conditions are satisfied.

Now the 2 hypothetical applications can differentiate their sockets
based on a mark value set with SO_MARK.

iptables -t mangle -I PREROUTING -m socket --transparent \
                                           --restore-skmark -j action
iptables -t mangle -A action -m mark --mark 10 -j action2
iptables -t mangle -A action -m mark --mark 11 -j action3

Change-Id: I962e87f32c241cb8d056dfd62f296fa312b05162
Signed-off-by: Harout Hedeshian &lt;harouth@codeaurora.org&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>xt_socket: add --nowildcard flag</title>
<updated>2015-10-06T09:30:27+00:00</updated>
<author>
<name>Eric Dumazet</name>
<email>edumazet@google.com</email>
</author>
<published>2015-08-22T01:21:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=29e08c5a8a9afca125b2c4ca9803add4f86a6e14'/>
<id>29e08c5a8a9afca125b2c4ca9803add4f86a6e14</id>
<content type='text'>
xt_socket module can be a nice replacement to conntrack module
in some cases (SYN filtering for example)

But it lacks the ability to match the 3rd packet of TCP
handshake (ACK coming from the client).

Add a XT_SOCKET_NOWILDCARD flag to disable the wildcard mechanism

The wildcard is the legacy socket match behavior, that ignores
LISTEN sockets bound to INADDR_ANY (or ipv6 equivalent)

iptables -I INPUT -p tcp --syn -j SYN_CHAIN
iptables -I INPUT -m socket -j ACCEPT

Change-Id: Ic5bbebbfccc1ccede0157cd3b5ea4863c1ed2fa7
Signed-off-by: Eric Dumazet &lt;edumazet@google.com&gt;
Cc: Patrick McHardy &lt;kaber@trash.net&gt;
Cc: Jesper Dangaard Brouer &lt;brouer@redhat.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
xt_socket module can be a nice replacement to conntrack module
in some cases (SYN filtering for example)

But it lacks the ability to match the 3rd packet of TCP
handshake (ACK coming from the client).

Add a XT_SOCKET_NOWILDCARD flag to disable the wildcard mechanism

The wildcard is the legacy socket match behavior, that ignores
LISTEN sockets bound to INADDR_ANY (or ipv6 equivalent)

iptables -I INPUT -p tcp --syn -j SYN_CHAIN
iptables -I INPUT -m socket -j ACCEPT

Change-Id: Ic5bbebbfccc1ccede0157cd3b5ea4863c1ed2fa7
Signed-off-by: Eric Dumazet &lt;edumazet@google.com&gt;
Cc: Patrick McHardy &lt;kaber@trash.net&gt;
Cc: Jesper Dangaard Brouer &lt;brouer@redhat.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>extensions: add hard idletimer xt target extension</title>
<updated>2015-10-06T09:30:26+00:00</updated>
<author>
<name>Susheel Yadagiri</name>
<email>syadagir@codeaurora.org</email>
</author>
<published>2014-06-20T23:26:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=3c931c53ce24a6bd8d0f94b3b2b1a0b90616c993'/>
<id>3c931c53ce24a6bd8d0f94b3b2b1a0b90616c993</id>
<content type='text'>
Add the extension plugin for the HARDIDLETIMER x_tables target

Change-Id: I318bc9f69f845b273c198bec80754eb5886e77d1
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add the extension plugin for the HARDIDLETIMER x_tables target

Change-Id: I318bc9f69f845b273c198bec80754eb5886e77d1
</pre>
</div>
</content>
</entry>
<entry>
<title>extensions: libxt_socket: add --restore-skmark option</title>
<updated>2015-07-29T07:54:07+00:00</updated>
<author>
<name>Harout Hedeshian</name>
<email>harouth@codeaurora.org</email>
</author>
<published>2015-06-16T00:41:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=de2fa7133374831bcb5080a43e567e2e41f84ee7'/>
<id>de2fa7133374831bcb5080a43e567e2e41f84ee7</id>
<content type='text'>
xt_socket is useful for matching sockets with IP_TRANSPARENT and
taking some action on the matching packets. However, it lacks the
ability to match only a small subset of transparent sockets.

Suppose there are 2 applications, each with its own set of transparent
sockets. The first application wants all matching packets dropped,
while the second application wants them forwarded somewhere else.

Add the ability to retore the skb-&gt;mark from the sk_mark. The mark
is only restored if a matching socket is found and the transparent /
nowildcard conditions are satisfied.

Now the 2 hypothetical applications can differentiate their sockets
based on a mark value set with SO_MARK.

iptables -t mangle -I PREROUTING -m socket --transparent \
                                           --restore-skmark -j action
iptables -t mangle -A action -m mark --mark 10 -j action2
iptables -t mangle -A action -m mark --mark 11 -j action3

Bug: 20663075
Signed-off-by: Harout Hedeshian &lt;harouth@codeaurora.org&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;

(cherry picked from commit 3b20fc71c99acd604d635deacef99769e36191b5)

Change-Id: If746841dea9db9f1c7ad1d74ed37fa13109e37ff
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
xt_socket is useful for matching sockets with IP_TRANSPARENT and
taking some action on the matching packets. However, it lacks the
ability to match only a small subset of transparent sockets.

Suppose there are 2 applications, each with its own set of transparent
sockets. The first application wants all matching packets dropped,
while the second application wants them forwarded somewhere else.

Add the ability to retore the skb-&gt;mark from the sk_mark. The mark
is only restored if a matching socket is found and the transparent /
nowildcard conditions are satisfied.

Now the 2 hypothetical applications can differentiate their sockets
based on a mark value set with SO_MARK.

iptables -t mangle -I PREROUTING -m socket --transparent \
                                           --restore-skmark -j action
iptables -t mangle -A action -m mark --mark 10 -j action2
iptables -t mangle -A action -m mark --mark 11 -j action3

Bug: 20663075
Signed-off-by: Harout Hedeshian &lt;harouth@codeaurora.org&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;

(cherry picked from commit 3b20fc71c99acd604d635deacef99769e36191b5)

Change-Id: If746841dea9db9f1c7ad1d74ed37fa13109e37ff
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge "xt_socket: add --nowildcard flag" into mnc-dr-dev</title>
<updated>2015-07-29T07:53:42+00:00</updated>
<author>
<name>Lorenzo Colitti</name>
<email>lorenzo@google.com</email>
</author>
<published>2015-07-29T07:53:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=fbb436cf1271a2868f5c55009bb8bf044a6aa809'/>
<id>fbb436cf1271a2868f5c55009bb8bf044a6aa809</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>xt_socket: add --nowildcard flag</title>
<updated>2015-07-29T07:23:06+00:00</updated>
<author>
<name>Eric Dumazet</name>
<email>edumazet@google.com</email>
</author>
<published>2013-06-20T12:52:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=586aef2c0dd9b6d534930994cc73b6d5a734854c'/>
<id>586aef2c0dd9b6d534930994cc73b6d5a734854c</id>
<content type='text'>
xt_socket module can be a nice replacement to conntrack module
in some cases (SYN filtering for example)

But it lacks the ability to match the 3rd packet of TCP
handshake (ACK coming from the client).

Add a XT_SOCKET_NOWILDCARD flag to disable the wildcard mechanism

The wildcard is the legacy socket match behavior, that ignores
LISTEN sockets bound to INADDR_ANY (or ipv6 equivalent)

iptables -I INPUT -p tcp --syn -j SYN_CHAIN
iptables -I INPUT -m socket -j ACCEPT

Bug: 20663075
Signed-off-by: Eric Dumazet &lt;edumazet@google.com&gt;
Cc: Patrick McHardy &lt;kaber@trash.net&gt;
Cc: Jesper Dangaard Brouer &lt;brouer@redhat.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
xt_socket module can be a nice replacement to conntrack module
in some cases (SYN filtering for example)

But it lacks the ability to match the 3rd packet of TCP
handshake (ACK coming from the client).

Add a XT_SOCKET_NOWILDCARD flag to disable the wildcard mechanism

The wildcard is the legacy socket match behavior, that ignores
LISTEN sockets bound to INADDR_ANY (or ipv6 equivalent)

iptables -I INPUT -p tcp --syn -j SYN_CHAIN
iptables -I INPUT -m socket -j ACCEPT

Bug: 20663075
Signed-off-by: Eric Dumazet &lt;edumazet@google.com&gt;
Cc: Patrick McHardy &lt;kaber@trash.net&gt;
Cc: Jesper Dangaard Brouer &lt;brouer@redhat.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge remote-tracking branch 'goog/mirror-m-wireless-internal-release' into master_merge</title>
<updated>2015-03-24T20:34:54+00:00</updated>
<author>
<name>Prerepa Viswanadham</name>
<email>dham@google.com</email>
</author>
<published>2015-03-24T20:34:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=79636552fc10f64f517a781546b3a00159ab6080'/>
<id>79636552fc10f64f517a781546b3a00159ab6080</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge "extensions: libxt_TEE: Trim kernel struct to allow deletion"</title>
<updated>2015-03-19T06:09:25+00:00</updated>
<author>
<name>Lorenzo Colitti</name>
<email>lorenzo@google.com</email>
</author>
<published>2015-03-19T06:09:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=0b0de5664c08f07a048fc8dc2048c95aa8f8c0bb'/>
<id>0b0de5664c08f07a048fc8dc2048c95aa8f8c0bb</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>extensions: libxt_TEE: Trim kernel struct to allow deletion</title>
<updated>2015-03-19T04:44:53+00:00</updated>
<author>
<name>Loganaden Velvindron</name>
<email>logan@elandsys.com</email>
</author>
<published>2014-11-09T14:15:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.replicant.us/mirrors/LineageOS/android_external_iptables/commit/?id=84e5e86b6dbfd4031b72d21ddca099dd4b3e7452'/>
<id>84e5e86b6dbfd4031b72d21ddca099dd4b3e7452</id>
<content type='text'>
Correct trimming of userspacesize to fix deletions.

Fixes: Bugzilla #884.

The rule having TEE target with '--oif' option cannot be deleted by iptables command.

  $ iptables -I INPUT -i foo -j TEE --gateway x.x.x.x --oif bar
  $ iptables -D INPUT -i foo -j TEE --gateway x.x.x.x --oif bar
  iptables: No chain/target/match by that name.

[Cherry-pick of iptables df3741332d86629a8fdd267930e0a249803f6aa8]

Signed-off-by: Loganaden Velvindron &lt;logan@elandsys.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
Change-Id: Ieb43487811669d502074330a0cba7c8d4c9c7446
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Correct trimming of userspacesize to fix deletions.

Fixes: Bugzilla #884.

The rule having TEE target with '--oif' option cannot be deleted by iptables command.

  $ iptables -I INPUT -i foo -j TEE --gateway x.x.x.x --oif bar
  $ iptables -D INPUT -i foo -j TEE --gateway x.x.x.x --oif bar
  iptables: No chain/target/match by that name.

[Cherry-pick of iptables df3741332d86629a8fdd267930e0a249803f6aa8]

Signed-off-by: Loganaden Velvindron &lt;logan@elandsys.com&gt;
Signed-off-by: Pablo Neira Ayuso &lt;pablo@netfilter.org&gt;
Change-Id: Ieb43487811669d502074330a0cba7c8d4c9c7446
</pre>
</div>
</content>
</entry>
</feed>
