On Mon, Jan 28, 2019 at 4:00 PM Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> wrote: > > From: Phil Sutter <phil@xxxxxx> > > To allow for a batch to contain rules in arbitrary ordering, introduce > NFTA_RULE_POSITION_ID attribute which works just like NFTA_RULE_POSITION > but contains the ID of another rule within the same batch. This helps > iptables-nft-restore handling dumps with mixed insert/append commands > correctly. > > Note that NFTA_RULE_POSITION takes precedence over > NFTA_RULE_POSITION_ID, so if the former is present, the latter is > ignored. It looks like you forgot to add NFTA_RULE_POSITION_ID into nft_rule_policy[]?