diff options
author | Phil Sutter <phil@nwl.cc> | 2024-03-05 16:28:29 +0100 |
---|---|---|
committer | Phil Sutter <phil@nwl.cc> | 2024-04-09 23:20:36 +0200 |
commit | d45fb0a4077304a7e3f2c44bbac1bde3a9b49a77 (patch) | |
tree | 7f8643ab3f4d692dbbcbf224e58b82de73893ddb /extensions/.owner-test6 | |
parent | 681935f6cb5734e120b5efe5aa8512508e2793f4 (diff) |
xlate: Improve redundant l4proto match avoidance
xtables-translate tries to avoid 'ip protocol'/'meta l4proto' matches if
following expressions add this as dependency anyway. E.g.:
| # iptables-translate -A FOO -p tcp -m tcp --dport 22 -j ACCEPT
| nft 'add rule ip filter FOO tcp dport 22 counter accept'
This worked by searching protocol name in loaded matches, but that
approach is flawed as the protocol name and corresponding extension may
differ ("mobility-header" vs. "mh"). Improve this by searching for all
names (cached or resolved) for a given protocol number.
Signed-off-by: Phil Sutter <phil@nwl.cc>
Diffstat (limited to 'extensions/.owner-test6')
0 files changed, 0 insertions, 0 deletions