authorFlorian Westphal <>2018-05-11 23:17:15 +0200
committerFlorian Westphal <>2018-05-14 01:24:26 +0200
commit1a696c99d278ca3fe551d891d21459cac6382aab (patch)
parentbb436ceb489c77c81074b3460ff11b62e8704695 (diff)
libxtables: store all requested match types
iptables and ip6tables don't need this because iptables is AF_INET, ip6tables AF_INET6, etc. But tools that can change af in-between such as nftables will then may then find to find such module. One example is conntrack, it offsers NFPROTO_IPV4 and NFPROTO_IPV6. When first loading with NFPROTO_IPV6, the IPV4 would be discarded. Signed-off-by: Florian Westphal <>
diff --git a/libxtables/xtables.c b/libxtables/xtables.c
index c5e86f38..f3966f15 100644
--- a/libxtables/xtables.c
+++ b/libxtables/xtables.c
@@ -933,9 +933,6 @@ void xtables_register_match(struct xtables_match *me)
if (me->extra_opts != NULL)
xtables_check_options(me->name, me->extra_opts);
- /* ignore not interested match */
- if (me->family != afinfo->family && me->family != AF_UNSPEC)
- return;
/* place on linked list of matches pending full registration */
me->next = xtables_pending_matches;