blob: 2616ab99f741074dab3afa6a583fd0a55420e0f2 [file] [log] [blame]
Patrick McHardyff968302006-05-24 16:15:03 +00001This module copies security markings from packets to connections
2(if unlabeled), and from connections back to packets (also only
3if unlabeled). Typically used in conjunction with SECMARK, it is
Mark Montaguedf37d992011-04-04 14:54:52 +02004valid in the
5.B security
6table (for backwards compatibility with older kernels, it is also
7valid in the
Patrick McHardyff968302006-05-24 16:15:03 +00008.B mangle
Mark Montaguedf37d992011-04-04 14:54:52 +02009table).
Patrick McHardyff968302006-05-24 16:15:03 +000010.TP
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010011\fB\-\-save\fP
Patrick McHardyff968302006-05-24 16:15:03 +000012If the packet has a security marking, copy it to the connection
13if the connection is not marked.
14.TP
Jan Engelhardtfea74bf2009-01-12 04:53:18 +010015\fB\-\-restore\fP
Patrick McHardyff968302006-05-24 16:15:03 +000016If the packet does not have a security marking, and the connection
17does, copy the security marking from the connection to the packet.
18