Re: nftables, after adding a rule without any action, nft doesn't return correctly

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

> Not a good idea to stick to old versions. We're still changing syntax
> in some aspects and resolving bugs at this stage. The user document
> aims to be in sync with latest. You should recommend people to stick
> to latest until 1.0 comes out.

Yes, I know.
Actually I wrote an article based on Fedora rawhide and it’s chasing nftables git tree with several days behind. Considering the development pace of nftables, it doesn’t matter for readers to use Fedora rawhide. Of course, I’m checking the latest tree in order to advise my readers to recognize the possibilities of changing syntax and so on.

Anyway, thank you for kindly advice!

Best Rio.

2014/07/17 23:14、Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx> のメール:

> On Thu, Jul 17, 2014 at 08:13:12AM +0900, Ryo Fujita wrote:
>> Hi Pablo-san and all,
>> 
>> Thank you so much!
>> You made me clear.
>> 
>>> You can add rules without any action.
>> 
>> I understand it’s the spec not a bug.
>> 
>>> Try -n to disabling name resolution:
>>> 
>>> # nft -n list table inet filter
>> 
>> 
>> Yes, I check that reverse lookup fails as you pointed out.
>> 
>>>> My environment was as followings.
>>>> nftables-0.100-3.20140704git.fc21.x86_64
>>> 
>>> Please, use latest when testing.
>>> 
>>> http://www.netfilter.org/projects/nftables/downloads.html
>> 
>> 
>> The reason why I’m using the slight old version is to write a
>> magazine article introducing nftables. It’s easy for readers to
>> install the version I checked with RPM or archive like
>> 'nftables-0.3’.  Anyway, I’ll test the latest before sending a
>> report to this ML.
> 
> Not a good idea to stick to old versions. We're still changing syntax
> in some aspects and resolving bugs at this stage. The user document
> aims to be in sync with latest. You should recommend people to stick
> to latest until 1.0 comes out.
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@xxxxxxxxxxxxxxx
> More majordomo info at  http://vger.kernel.org/majordomo-info.html

########################################################################
Ryo Fujita <rfujita@xxxxxxxxxx>
Supervisor, Solution Architects, RHCE
Red Hat K.K.
TEL +81-3-5798-8500 FAX +81-3-5798-8599
Ebisu Neonato 8F, 4-1-18 Ebisu, Shibuya-ku, Tokyo Japan 1500013

レッドハット株式会社
グローバルサービス本部プラットフォームソリューション統括部
ソリューションアーキテクト部長
藤田 稜
〒150-0013
東京都渋谷区恵比寿4-1-18 恵比寿ネオナート8階
Tel 03-5798-8500
http://www.jp.redhat.com/

Please consider the environment before printing this e-mail.
########################################################################

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux