diff options
author | Phil Sutter <phil@nwl.cc> | 2024-02-27 18:47:39 +0100 |
---|---|---|
committer | Phil Sutter <phil@nwl.cc> | 2024-02-27 19:41:02 +0100 |
commit | bb1a7a5b297aa271f7f59abbcb891cd94d7fb305 (patch) | |
tree | 57e06b2850481fd6466bfe357b7a4d4bfd1b6a9f /extensions/libip6t_frag.man | |
parent | ff57cd48d2b0c01c1519fd8893fc0432ad211702 (diff) |
nft: Fix for broken recover_rule_compat()
When IPv4 rule generator was changed to emit payload instead of
meta expressions for l4proto matches, the code reinserting
NFTNL_RULE_COMPAT_* attributes into rules being reused for counter
zeroing was broken by accident.
Make rule compat recovery aware of the alternative match, basically
reinstating the effect of commit 7a373f6683afb ("nft: Fix -Z for rules
with NFTA_RULE_COMPAT") but add a test case this time to make sure
things stay intact.
Fixes: 69278f9602b43 ("nft: use payload matching for layer 4 protocol")
Signed-off-by: Phil Sutter <phil@nwl.cc>
Diffstat (limited to 'extensions/libip6t_frag.man')
0 files changed, 0 insertions, 0 deletions