Re: [PATCH nft] tests: nft removes required payload protocol expressions

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote:
> On Thu, Mar 23, 2017 at 09:11:56AM +0100, Florian Westphal wrote:
> > This test fails with
> > 'ip protocol tcp tcp dport 22' mismatches 'tcp dport 22'
> > 
> > ip protocol tcp tcp dport 22 is *ONLY* identical to
> > 'tcp dport 22' in the ip family.
> > 
> > For netdev/inet/bridge, the dependency is required because
> > we only want to match ipv4 packets.
> 
> This needs the C chunk to fix this, right? so I let you decide if you
> want to push out this test now or make it together with the fix.

I have no fix at the moment.

I will thus probably push this test when I get home so we don't forget
about it.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux