Twitter | Pretraživanje | |
Dmitry Vyukov
Brace yourselves, more netfilter bugs are coming! Bets on number of bugs in the first week
Reply Retweet Označi sa "sviđa mi se" More
Dmitry Vyukov 15. sij
Odgovor korisniku/ci @dvyukov
I thought netfilter/iptables is an attempt to build . No, turns out it's an attempt to build twice Get a taste of API surface:
Reply Retweet Označi sa "sviđa mi se"
Dmitry Vyukov 15. sij
Odgovor korisniku/ci @dvyukov
Now, turns out there is also "netfilter tables API": which reimplements all of the same with another set of expressions, objects, containers, registers, control flow, etc _and_ also includes all of the legacy "xtables" recursively:
Reply Retweet Označi sa "sviđa mi se"
Dmitry Vyukov 15. sij
Odgovor korisniku/ci @dvyukov
nf_table_api.c (just a subpart) is 8K lines of complex stateful C code: Wonder what amount of resources was put into testing all of this... Like really testing, not just on few expected scenarios. All of this is open to any unpriv user and containers.
Reply Retweet Označi sa "sviđa mi se"