Blame bootstrap_ver/extensions/libxt_cgroup.man

Packit Service dd8e2b
.TP
Packit Service dd8e2b
[\fB!\fP] \fB\-\-path\fP \fIpath\fP
Packit Service dd8e2b
Match cgroup2 membership.
Packit Service dd8e2b
Packit Service dd8e2b
Each socket is associated with the v2 cgroup of the creating process.
Packit Service dd8e2b
This matches packets coming from or going to all sockets in the
Packit Service dd8e2b
sub-hierarchy of the specified path.  The path should be relative to
Packit Service dd8e2b
the root of the cgroup2 hierarchy.
Packit Service dd8e2b
.TP
Packit Service dd8e2b
[\fB!\fP] \fB\-\-cgroup\fP \fIclassid\fP
Packit Service dd8e2b
Match cgroup net_cls classid.
Packit Service dd8e2b
Packit Service dd8e2b
classid is the marker set through the cgroup net_cls controller.  This
Packit Service dd8e2b
option and \-\-path can't be used together.
Packit Service dd8e2b
.PP
Packit Service dd8e2b
Example:
Packit Service dd8e2b
.IP
Packit Service dd8e2b
iptables \-A OUTPUT \-p tcp \-\-sport 80 \-m cgroup ! \-\-path service/http-server \-j DROP
Packit Service dd8e2b
.IP
Packit Service dd8e2b
iptables \-A OUTPUT \-p tcp \-\-sport 80 \-m cgroup ! \-\-cgroup 1
Packit Service dd8e2b
\-j DROP
Packit Service dd8e2b
.PP
Packit Service dd8e2b
\fBIMPORTANT\fP: when being used in the INPUT chain, the cgroup
Packit Service dd8e2b
matcher is currently only of limited functionality, meaning it
Packit Service dd8e2b
will only match on packets that are processed for local sockets
Packit Service dd8e2b
through early socket demuxing. Therefore, general usage on the
Packit Service dd8e2b
INPUT chain is not advised unless the implications are well
Packit Service dd8e2b
understood.
Packit Service dd8e2b
.PP
Packit Service dd8e2b
Available since Linux 3.14.