3 ms·
Just to expand this answers; this is not a tcp wrapper replacement. I mean, it can be used as one; but that's just a side effect. Since linux 4.10 you can atta
by hiciu 9y ago
Just to expand this answers; this is not a tcp wrapper replacement. I mean, it can be used as one; but that's just a side effect.
Since linux 4.10 you can attach eBPF programs to the cgroups: https://kernelnewbies.org/Linux_4.10#head-4f00d500db4f8e437a5ad6005d9cf39ee0124bec https://kernelnewbies.org/Linux_4.10#head-4f00d500db4f8e437a.... This allows you to do a really cool things, mostly firewalls attached to the cgroup and not to the system-wide netfilter stack. Imagine application-specific firewalls.
Systemd uses that to add "simple" packet counting eBPF application to the cgroups: https://github.com/systemd/systemd/commit/1988a9d12015990c145a6e8515d5e22ef88b32cb https://github.com/systemd/systemd/commit/1988a9d12015990c14....
(eBPF is the same mechanism that is used with seccomp and filtering which syscalls can application use and which are forbidden - used in for example chromium sandbox on linux or with openssh)