Re: [PATCH net 1/2] netfilter: conntrack: skip identical origin tuple in same zone only

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello:

This series was applied to netdev/net.git (refs/heads/master):

On Tue,  9 Feb 2021 22:35:10 +0100 you wrote:
> From: Florian Westphal <fw@xxxxxxxxx>
> 
> The origin skip check needs to re-test the zone. Else, we might skip
> a colliding tuple in the reply direction.
> 
> This only occurs when using 'directional zones' where origin tuples
> reside in different zones but the reply tuples share the same zone.
> 
> [...]

Here is the summary with links:
  - [net,1/2] netfilter: conntrack: skip identical origin tuple in same zone only
    https://git.kernel.org/netdev/net/c/07998281c268
  - [net,2/2] netfilter: nftables: relax check for stateful expressions in set definition
    https://git.kernel.org/netdev/net/c/664899e85c13

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html





[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux