Re: NOTRACK removal breaks working configurations

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Dec 20, 2012 at 01:28:39PM +0100, Florian Westphal wrote:
> Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > > commit 965505015beccc4ec900798070165875b8e8dccf
> > > Author: Cong Wang <xiyou.wangcong@xxxxxxxxx>
> > > Subject: netfilter: remove xt_NOTRACK
> > > 
> > > It breaks working netfilter configurations.
> > > At the very least, NOTRACK should have printk'd
> > > 
> > > BIG FAT REMOVAL WARNING
> > > 
> > > for a year or so.  Which it didn't do.
> > 
> > This was announced in Documentation/feature-removal-schedule.txt and
> > the aliasing infrastructure was added to iptables
> 
> I know.
> 
> > it was agressive since I think not many users have checked that file /
> > they may no have upgrade iptables to latest.
> 
> Right.
> 
> > Can you see any problem with the patch attached?
> 
> No.  The patch works.
> [   21.870092] xt_CT: netfilter: NOTRACK target is deprecated, use CT instead or upgrade iptables
> 
> Even better than a revert.

Thanks, I'll pass this to David in the next batch and then ask for
-stable submission.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux