• Pablo Neira Ayuso's avatar
    netfilter: nf_tables: add support for dormant tables · 9ddf6323
    Pablo Neira Ayuso authored
    This patch allows you to temporarily disable an entire table.
    You can change the state of a dormant table via NFT_MSG_NEWTABLE
    messages. Using this operation you can wake up a table, so their
    chains are registered.
    
    This provides atomicity at chain level. Thus, the rule-set of one
    chain is applied at once, avoiding any possible intermediate state
    in every chain. Still, the chains that belongs to a table are
    registered consecutively. This also allows you to have inactive
    tables in the kernel.
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    9ddf6323
nf_tables_api.c 72.6 KB