From: Daniel Borkmann
Date: Tue, 06 Jun 2017 22:27:15 +0200
> On 06/06/2017 10:26 PM, David Miller wrote:
>> From: Chenbo Feng
>> Date: Tue, 6 Jun 2017 13:24:11 -0700
>>
>>> On Tue, Jun 6, 2017 at 9:40 AM, Daniel Borkmann
>>> wrote:
>>>
On 06/06/2017 02:04 PM, Daniel Borkmann wrote:
>
On 06/06/2017 10:26 PM, David Miller wrote:
From: Chenbo Feng
Date: Tue, 6 Jun 2017 13:24:11 -0700
On Tue, Jun 6, 2017 at 9:40 AM, Daniel Borkmann
wrote:
On 06/06/2017 02:04 PM, Daniel Borkmann wrote:
On 06/01/2017 03:15 AM, Chenbo Feng wrote:
From: Chenbo Feng
This allows cgroup eBPF
From: Chenbo Feng
Date: Tue, 6 Jun 2017 13:24:11 -0700
> On Tue, Jun 6, 2017 at 9:40 AM, Daniel Borkmann
> wrote:
>
>> On 06/06/2017 02:04 PM, Daniel Borkmann wrote:
>>
>>> On 06/01/2017 03:15 AM, Chenbo Feng wrote:
>>>
From: Chenbo Feng
This allows cgroup eBPF program to classi
On 06/06/2017 02:04 PM, Daniel Borkmann wrote:
On 06/01/2017 03:15 AM, Chenbo Feng wrote:
From: Chenbo Feng
This allows cgroup eBPF program to classify packet based on their
protocol or other detail information. Currently program need
CAP_NET_ADMIN privilege to attach a cgroup eBPF program, an
On 06/01/2017 03:15 AM, Chenbo Feng wrote:
From: Chenbo Feng
This allows cgroup eBPF program to classify packet based on their
protocol or other detail information. Currently program need
CAP_NET_ADMIN privilege to attach a cgroup eBPF program, and A
process with CAP_NET_ADMIN can already see a
From: Chenbo Feng
Date: Wed, 31 May 2017 18:15:59 -0700
> From: Chenbo Feng
>
> This allows cgroup eBPF program to classify packet based on their
> protocol or other detail information. Currently program need
> CAP_NET_ADMIN privilege to attach a cgroup eBPF program, and A
> process with CAP_NE
On Wed, May 31, 2017 at 06:15:59PM -0700, Chenbo Feng wrote:
> From: Chenbo Feng
>
> This allows cgroup eBPF program to classify packet based on their
> protocol or other detail information. Currently program need
> CAP_NET_ADMIN privilege to attach a cgroup eBPF program, and A
> process with CAP
From: Chenbo Feng
This allows cgroup eBPF program to classify packet based on their
protocol or other detail information. Currently program need
CAP_NET_ADMIN privilege to attach a cgroup eBPF program, and A
process with CAP_NET_ADMIN can already see all packets on the system,
for example, by cre