Robert Ly | 35f2fda | 2013-01-29 16:27:05 -0800 | [diff] [blame] | 1 | page.title=Kernel Changes |
| 2 | @jd:body |
| 3 | |
| 4 | <!-- |
Clay Murphy | 768b82a | 2013-11-12 11:32:41 -0800 | [diff] [blame^] | 5 | Copyright 2013 The Android Open Source Project |
Robert Ly | 35f2fda | 2013-01-29 16:27:05 -0800 | [diff] [blame] | 6 | |
| 7 | Licensed under the Apache License, Version 2.0 (the "License"); |
| 8 | you may not use this file except in compliance with the License. |
| 9 | You may obtain a copy of the License at |
| 10 | |
| 11 | http://www.apache.org/licenses/LICENSE-2.0 |
| 12 | |
| 13 | Unless required by applicable law or agreed to in writing, software |
| 14 | distributed under the License is distributed on an "AS IS" BASIS, |
| 15 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 16 | See the License for the specific language governing permissions and |
| 17 | limitations under the License. |
| 18 | --> |
| 19 | <p>This is a summary of the main changes in the kernel that diverge from mainline.</p> |
| 20 | <ul> |
| 21 | <li>added net/netfilter/xt_qtaguid*</li> |
| 22 | <li>imported then modified net/netfilter/xt_quota2.c from xtables-addons project</li> |
| 23 | <li>fixes in net/netfilter/ip6_tables.c</li> |
| 24 | <li>modified ip*t_REJECT.c</li> |
| 25 | <li>modified net/netfilter/xt_socket.c</li> |
| 26 | </ul> |
| 27 | <p>A few comments on the kernel configuration:</p> |
| 28 | <ul> |
| 29 | <li>xt_qtaguid masquerades as xt_owner and relies on xt_socket and itself relies on the connection tracker.</li> |
| 30 | <li>The connection tracker can't handle large SIP packets, it must be disabled.</li> |
| 31 | <li>The modified xt_quota2 uses the NFLOG support to notify userspace.</li> |
| 32 | </ul> |