On Thu, 31 Jan 2013, Pablo Neira Ayuso wrote: > On Wed, Jan 30, 2013 at 10:05:19PM +0100, Jozsef Kadlecsik wrote: > > Hi Pablo, > > > > On Mon, 28 Jan 2013, Jozsef Kadlecsik wrote: > > > > > The next patches introduce the alias support for matches and targets in > > > iptables. The goal is to keep the old syntax of matches/targets merged > > > into "super" matches/targets. This way firewall scripts can run unmodified, > > > using the old extensions. > > > > > > The NOTRACK alias requires a new revision of the CT target (flags are checked > > > in the current revision). Next follows the kernel part of the patches. Until > > > the new revision is missing, instead of the warning, a notice is printed > > > to the users. > > > > > > Please comment/ACK the patches. > > > > Is it OK then to apply these patches in the git tree of iptables? > > You can apply the basic symmetric aliasing infrastructure plus the > state match to the stable branch. > > The aliasing for the CT target would have to wait in the next branch > of iptables until 3.9-rc1 is released. The patches are applied except the last one for the CT target. Best regards Jozsef - E-mail : kadlec@xxxxxxxxxxxxxxxxx, kadlecsik.jozsef@xxxxxxxxxxxxx PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt Address : Wigner Research Centre for Physics, Hungarian Academy of Sciences H-1525 Budapest 114, POB. 49, Hungary -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html