From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-7.1 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE, SPF_PASS,URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 12451C433E2 for ; Mon, 7 Sep 2020 22:11:45 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id DD9B1215A4 for ; Mon, 7 Sep 2020 22:11:44 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727838AbgIGWLl (ORCPT ); Mon, 7 Sep 2020 18:11:41 -0400 Received: from www62.your-server.de ([213.133.104.62]:32838 "EHLO www62.your-server.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727103AbgIGWLk (ORCPT ); Mon, 7 Sep 2020 18:11:40 -0400 Received: from sslproxy02.your-server.de ([78.47.166.47]) by www62.your-server.de with esmtpsa (TLSv1.2:DHE-RSA-AES256-GCM-SHA384:256) (Exim 4.89_1) (envelope-from ) id 1kFPMB-000321-Rm; Tue, 08 Sep 2020 00:11:23 +0200 Received: from [178.196.57.75] (helo=pc-9.home) by sslproxy02.your-server.de with esmtpsa (TLSv1.3:TLS_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1kFPMB-000Kx6-HZ; Tue, 08 Sep 2020 00:11:23 +0200 Subject: Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook To: =?UTF-8?Q?Laura_Garc=c3=ada_Li=c3=a9bana?= Cc: Lukas Wunner , John Fastabend , Pablo Neira Ayuso , Jozsef Kadlecsik , Florian Westphal , Netfilter Development Mailing list , coreteam@netfilter.org, netdev@vger.kernel.org, Alexei Starovoitov , Eric Dumazet , Thomas Graf , David Miller References: <20200904162154.GA24295@wunner.de> <813edf35-6fcf-c569-aab7-4da654546d9d@iogearbox.net> From: Daniel Borkmann Message-ID: Date: Tue, 8 Sep 2020 00:11:22 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.7.2 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 8bit X-Authenticated-Sender: daniel@iogearbox.net X-Virus-Scanned: Clear (ClamAV 0.102.4/25923/Mon Sep 7 15:37:02 2020) Sender: netfilter-devel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netfilter-devel@vger.kernel.org On 9/5/20 1:18 PM, Laura García Liébana wrote: > On Fri, Sep 4, 2020 at 11:14 PM Daniel Borkmann wrote: [...] > Something like this seems more trivial to me: > > table netdev mytable { > chain mychain { > type filter hook egress device "eth0" priority 100; policy drop; > meta protocol != 0x419C accept > } > } Sure, different frontends, so what?! You could also wrap that code into a simple a.out or have nft style syntax jit to bpf ...