diff options
author | Maciej Zenczykowski <maze@google.com> | 2011-04-04 15:31:43 +0200 |
---|---|---|
committer | Patrick McHardy <kaber@trash.net> | 2011-04-04 15:31:43 +0200 |
commit | 2c6ac071a9c660b61a76565d1024d372deac8a98 (patch) | |
tree | 772761160fc86b1be650fa185fb55338fd7225e7 /INCOMPATIBILITIES | |
parent | cf3e52d00b7d3fedf98ef7710c337c441270d936 (diff) |
xtables: delay (statically built) match/target initialization
Matches and targets built into the iptables static binary will always
be registered as the binary starts up, this may potentially (as a result
of kernel version support checking) result in modules being autoloaded.
This is undesirable (for example it may cause CONNMARK target to load
and thus cause the kernel to load the conntrack module, which isn't a
no-op).
Transition to a system where matches and targets are registered into
a pending list, from whence they get fully registered only when
required.
Signed-off-by: Maciej Zenczykowski <maze@google.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Diffstat (limited to 'INCOMPATIBILITIES')
0 files changed, 0 insertions, 0 deletions