libvirt/src
Stefan Berger 552bdb9b35 nwfilter: Fix instantiated layer 2 rules for 'inout' direction
With Eric Blake's suggestions applied.

The following rule for direction 'in'

<rule direction='in' action='drop'>
  <mac srcmacaddr='1:2:3:4:5:6'/>
</rule>

drops all traffic from the given mac address.
The following rule for direction 'out'

<rule direction='out' action='drop'>
  <mac dstmacaddr='1:2:3:4:5:6'/>
</rule>

drops all traffic to the given mac address.
The following rule in direction 'inout'

<rule direction='inout' action='drop'>
  <mac srcmacaddr='1:2:3:4:5:6'/>
</rule>

now drops all traffic from and to the given MAC address.
So far it would have dropped traffic from the given MAC address
and outgoing traffic with the given source MAC address, which is not useful
since the packets will always have the VM's MAC address as source
MAC address. The attached patch fixes this.

This is the last bug I currently know of and want to fix.
2010-04-06 10:40:35 -04:00
..
conf This patch fixes some compilation issues for the RHEL5 build. I am also removing the IPV6 constant where it appears in the wrong place. 2010-04-06 06:29:00 -04:00
cpu cpuUpdate() for updating guest CPU according to host CPU 2010-03-26 23:01:58 +01:00
esx Snapshot API framework. 2010-04-05 10:24:34 -04:00
interface netcf: Remove virConnectPtr from interfaceReportError 2010-04-06 01:47:02 +02:00
lxc Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
network build: consistently indent preprocessor directives 2010-03-09 19:22:28 +01:00
node_device Remove unnecessary trailing \n in log messages 2010-04-06 01:41:58 +02:00
nwfilter nwfilter: Fix instantiated layer 2 rules for 'inout' direction 2010-04-06 10:40:35 -04:00
opennebula Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
openvz openvz: Remove virConnectPtr from openvzError 2010-04-06 02:04:50 +02:00
phyp Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
qemu Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
remote Remove unnecessary trailing \n in log messages 2010-04-06 01:41:58 +02:00
secret build: consistently indent preprocessor directives 2010-03-09 19:22:28 +01:00
security Fix compiler warning about non-literal format string 2010-04-06 01:38:53 +02:00
storage Remove unnecessary trailing \n in log messages 2010-04-06 01:41:58 +02:00
test test: Remove virConnectPtr from testError 2010-04-06 01:41:58 +02:00
uml Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
util Snapshot API framework. 2010-04-05 10:24:34 -04:00
vbox Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
xen Fix up comments for isEncrypted, isSecure, domainIsActive, 2010-04-06 09:51:24 -04:00
xenapi Snapshot API framework. 2010-04-05 10:24:34 -04:00
.gitignore Add virt-aa-helper and secaatest to .gitignore 2010-03-31 13:36:54 +02:00
datatypes.c Remove virConnectPtr from virLibConnError 2010-04-06 02:01:51 +02:00
datatypes.h Snapshot API framework. 2010-04-05 10:24:34 -04:00
driver.c Remote driver & daemon impl of new event API 2010-03-26 13:52:29 +00:00
driver.h Snapshot API framework. 2010-04-05 10:24:34 -04:00
gnutls_1_0_compat.h build: consistently indent preprocessor directives 2010-03-09 19:22:28 +01:00
internal.h Refactor major.minor.micro version parsing into a function 2010-04-01 12:53:41 +02:00
libvirt_bridge.syms Support networking in UML driver 2009-06-03 11:13:33 +00:00
libvirt_daemon.syms Export conditional state driver symbols only when they are defined 2010-03-23 02:05:18 +01:00
libvirt_driver_modules.syms Move --with-driver-modules symbols into a separate sym file 2009-01-05 14:06:41 +00:00
libvirt_internal.h build: consistently indent preprocessor directives 2010-03-09 19:22:28 +01:00
libvirt_linux.syms migrate linux-specific symbol names into their own sym file 2009-01-05 14:08:26 +00:00
libvirt_macvtap.syms macvtap teardown rework 2010-02-18 15:13:48 +01:00
libvirt_private.syms Snapshot internal methods. 2010-04-05 10:24:38 -04:00
libvirt_public.syms Snapshot API framework. 2010-04-05 10:24:34 -04:00
libvirt.c Snapshot API framework. 2010-04-05 10:24:34 -04:00
Makefile.am Keep build quiet for generated file 2010-04-01 12:35:51 +01:00
nodeinfo.c Fix compiler warning about unused conn parameter 2010-04-06 11:47:28 +02:00
nodeinfo.h build: consistently indent preprocessor directives 2010-03-09 19:22:28 +01:00
README Add a README file to src/ explaining the directory structure 2009-09-21 14:41:47 +01:00

       libvirt library code README
       ===========================

The directory provides the bulk of the libvirt codebase. Everything
except for the libvirtd daemon and client tools. The build uses a
large number of libtool convenience libraries - one for each child
directory, and then links them together for the final libvirt.so,
although some bits get linked directly to libvirtd daemon instead.

The files directly in this directory are supporting the public API
entry points & data structures.

There are two core shared modules to be aware of:

 * util/  - a collection of shared APIs that can be used by any
            code. This directory is always in the include path
            for all things built

 * conf/  - APIs for parsing / manipulating all the official XML
            files used by the public API. This directory is only
            in the include path for driver implementation modules


Then there are the hypervisor implementations:

 * esx/          - VMware ESX and GSX support using vSphere API over SOAP
 * lxc/          - Linux Native Containers
 * opennebula/   - Open Nebula using XMLRPC
 * openvz/       - OpenVZ containers using cli tools
 * phyp/         - IBM Power Hypervisor using CLI tools over SSH
 * qemu/         - QEMU / KVM using qemu CLI/monitor
 * remote/       - Generic libvirt native RPC client
 * test/         - A "mock" driver for testing
 * uml/          - User Mode Linux
 * vbox/         - Virtual Box using native API
 * xen/          - Xen using hypercalls, XenD SEXPR & XenStore


Finally some secondary drivers that are shared for several HVs.
Currently these are used by LXC, OpenVZ, QEMU, UML and Xen drivers.
The ESX, OpenNebula, Power Hypervisor, Remote, Test & VirtualBox
drivers all implement the secondary drivers directly

 * interface/    - Host network interface management
 * network/      - Virtual NAT networking
 * node_device/  - Host device enumeration
 * secret/       - Secret management
 * security/     - Mandatory access control drivers
 * storage/      - Storage management drivers


Since both the hypervisor and secondary drivers can be built as
dlopen()able modules, it is *FORBIDDEN* to have build dependencies
between these directories. Drivers are only allowed to depend on
the public API, and the internal APIs in the util/ and conf/
directories