Re: [PATCH nf-next 1/2] netfilter: nf_tables: add chain to pktinfo structure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Nov 28, 2016 at 01:56:49AM +0100, Florian Westphal wrote:
> Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> > This patch adds the chain object to the pktinfo structure. This
> > potentially allow us to know what basechain this packet is walking over
> > from the expression evaluation path.
> 
> ... for what?  Why...?

Quota depletion event notification needs to know from what table
delivery is happening, so this one actually belongs to the stateful
object patchset..

> Its not clear to me why these changes are made.  Same for patch #2.

Patch #2 used to be required by the original stateful object
infrastructure, but actually, last version doesn't need this. When
decoupling the stateful object from the expression, the NFT_OBJECT_*
are used. I can keep this back so we can escape this extra complexity.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux