The functions that allows you to create built-in table and chains are required out of the scope of nft.c Signed-off-by: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> --- iptables/nft.c | 14 +++++++------- iptables/nft.h | 5 ----- 2 files changed, 7 insertions(+), 12 deletions(-) diff --git a/iptables/nft.c b/iptables/nft.c index b68b275..33afae4 100644 --- a/iptables/nft.c +++ b/iptables/nft.c @@ -518,7 +518,7 @@ static int nft_table_builtin_add(struct nft_handle *h, return ret; } -struct nft_chain * +static struct nft_chain * nft_chain_builtin_alloc(struct builtin_table *table, struct builtin_chain *chain, int policy) { @@ -561,8 +561,9 @@ int nft_chain_add(struct nft_handle *h, struct nft_chain *c, uint16_t flags) return mnl_talk(h, nlh, NULL, NULL); } -void nft_chain_builtin_add(struct nft_handle *h, struct builtin_table *table, - struct builtin_chain *chain, int policy) +static void nft_chain_builtin_add(struct nft_handle *h, + struct builtin_table *table, + struct builtin_chain *chain, int policy) { struct nft_chain *c; @@ -598,7 +599,7 @@ nft_table_builtin_find(struct nft_handle *h, const char *table) } /* find if built-in chain already exists */ -struct builtin_chain * +static struct builtin_chain * nft_chain_builtin_find(struct builtin_table *t, const char *chain) { int i; @@ -643,9 +644,8 @@ __nft_chain_builtin_init(struct nft_handle *h, nft_chain_list_free(list); } -int -nft_chain_builtin_init(struct nft_handle *h, const char *table, - const char *chain, int policy) +static int nft_chain_builtin_init(struct nft_handle *h, const char *table, + const char *chain, int policy) { int ret = 0; struct builtin_table *t; diff --git a/iptables/nft.h b/iptables/nft.h index 339d7bc..0db2ed6 100644 --- a/iptables/nft.h +++ b/iptables/nft.h @@ -54,7 +54,6 @@ void nft_fini(struct nft_handle *h); struct nft_table; struct nft_chain_list; -struct builtin_table *nft_table_builtin_find(struct nft_handle *h, const char *table); int nft_table_add(struct nft_handle *h, struct nft_table *t, uint16_t flags); int nft_for_each_table(struct nft_handle *h, int (*func)(struct nft_handle *h, const char *tablename, bool counters), bool counters); bool nft_table_find(struct nft_handle *h, const char *tablename); @@ -65,10 +64,6 @@ int nft_table_purge_chains(struct nft_handle *h, const char *table, struct nft_c */ struct nft_chain; -struct nft_chain *nft_chain_builtin_alloc(struct builtin_table *table, struct builtin_chain *chain, int policy); -void nft_chain_builtin_add(struct nft_handle *h, struct builtin_table *table, struct builtin_chain *chain, int policy); -struct builtin_chain *nft_chain_builtin_find(struct builtin_table *t, const char *chain); -int nft_chain_builtin_init(struct nft_handle *h, const char *table, const char *chain, int policy); int nft_chain_add(struct nft_handle *h, struct nft_chain *c, uint16_t flags); int nft_chain_set(struct nft_handle *h, const char *table, const char *chain, const char *policy, const struct xt_counters *counters); struct nft_chain_list *nft_chain_dump(struct nft_handle *h); -- 1.7.10.4 -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html