Re: [PATCH 1/2 nftables] src: introduce passive OS fingerprint matching

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



BTW, we need a follow up patch.

If the osf extension is used, then nft should automagically load the
pf.os file under /etc/nftables/pf.os. This should only happen if only
if the osf extension is used.

Like this, we don't need to explicit run "nfnl_osf".

Then next question is:

a) Should we just import iptables/utils/nfnl_osf.c into nftables and
   use it. So we keep two copies in the tree?

b) We add a libnetfilter_osf library, probably too much for a small
   codebase, but I don't like code redundancy. Not sure..

Any comments?

In any case, would you work on this?

Thanks!
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux