blob: b635e7d9bf9590995ee7eeb06e1dad6696da0430 [file] [log] [blame]
Henrik Nordstromc2794132004-01-22 15:04:24 +00001This module attempts to match various characteristics of the packet
2creator, for locally-generated packets. It is only valid in the
3.B OUTPUT
4chain, and even this some packets (such as ICMP ping responses) may
5have no owner, and hence never match.
6.TP
7.BI "--uid-owner " "userid"
8Matches if the packet was created by a process with the given
9effective user id.
10.TP
11.BI "--gid-owner " "groupid"
12Matches if the packet was created by a process with the given
13effective group id.
14.TP
15.BI "--pid-owner " "processid"
16Matches if the packet was created by a process with the given
17process id.
18.TP
19.BI "--sid-owner " "sessionid"
20Matches if the packet was created by a process in the given session
21group.
22.TP
23.BI "--cmd-owner " "name"
24Matches if the packet was created by a process with the given command name.
25(this option is present only if iptables was compiled under a kernel
26supporting this feature)
Patrick McHardy373f8e92004-10-03 20:36:54 +000027.TP
28.B NOTE: pid, sid and command matching are broken on SMP