diff options
author | Phil Sutter <phil@nwl.cc> | 2023-08-10 11:30:59 +0200 |
---|---|---|
committer | Phil Sutter <phil@nwl.cc> | 2023-08-10 14:14:25 +0200 |
commit | 39a067bb3b1b4ffb50a925f66e7db56658c0dfa7 (patch) | |
tree | 528bfdcafa0d92ad0ce601a0018aa94c6f078fee /iptables/tests/shell | |
parent | 5412ccba55b2318160d32efec3b8aad162608af9 (diff) |
nft: Create builtin chains with counters enabled
The kernel enables policy counters for nftables chains only if
NFTA_CHAIN_COUNTERS attribute is present. For this to be generated, one
has to set NFTNL_CHAIN_PACKETS and NFTNL_CHAIN_BYTES attributes in the
allocated nftnl_chain object.
The above happened for base chains only with iptables-nft-restore if
called with --counters flag. Since this is very unintuitive to users,
fix the situation by adding counters to base chains in any case.
Fixes: 384958620abab ("use nf_tables and nf_tables compatibility interface")
Signed-off-by: Phil Sutter <phil@nwl.cc>
Diffstat (limited to 'iptables/tests/shell')
0 files changed, 0 insertions, 0 deletions