Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Pablo,

On Wed, Apr 26, 2023 at 09:58:44PM +0200, Pablo Neira Ayuso wrote:
[...]
> My proposal:

Thanks for returning to this. Your approach requires to define a minimum
version from which on forward-compat is guaranteed. I was trying to
avoid this requirement though so things would work for "unknown user
space".

Currently, the only offending extension is ebt_among since it doesn't
exist (and never did) in non-native form. If I implement among extension
parsing (even in non-functional form), my original approach would work.
This also means having a minimum version for full compat, but it affects
ebtables (actually, use of ebt_among) only.

Cheers, Phil



[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux