From: Roberto García <rodanber@xxxxxxxxx> Fix translation of MARK target's --set-xmark option. Before: # iptables-translate -t mangle -A PREROUTING -j MARK --set-xmark 0x64/0xaf nft add rule ip mangle PREROUTING counter meta mark set mark xor 0x64 and 0xaf After: # iptables-translate -t mangle -A PREROUTING -j MARK --set-xmark 0x64/0xaf nft add rule ip mangle PREROUTING counter meta mark set mark xor 0x64 and \ 0xffffff50 Signed-off-by: Roberto García <rodanber@xxxxxxxxx> --- extensions/libxt_MARK.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extensions/libxt_MARK.c b/extensions/libxt_MARK.c index ec1ed05..12ab94f 100644 --- a/extensions/libxt_MARK.c +++ b/extensions/libxt_MARK.c @@ -262,7 +262,7 @@ static int mark_tg_xlate(const void *ip, const struct xt_entry_target *target, xt_xlate_add(xl, "0x%x ", info->mark); else xt_xlate_add(xl, "mark xor 0x%x and 0x%x ", info->mark, - info->mask); + ~info->mask); return 1; } -- 2.8.0 -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html