Thread (31 messages) flat view 31 messages, 4 authors, 2014-01-10

Re: [PATCH 08/23] netfilter: nft_ct: load both IPv4 and IPv6 conntrack modules for NFPROTO_INET

From: Patrick McHardy <hidden>
Date: 2014-01-10 19:42:40
Also in: netfilter-devel

On Fri, Jan 10, 2014 at 11:40:38PM +0300, Sergei Shtylyov wrote:
On 01/10/2014 03:35 AM, Pablo Neira Ayuso wrote:
quoted
From: Patrick McHardy <redacted>
quoted
The ct expression can currently not be used in the inet family since
we don't have a conntrack module for NFPROTO_INET, so
nf_ct_l3proto_try_module_get() fails. Add some manual handling to
load the modules for both NFPROTO_IPV4 and NFPROTO_IPV6 if the
ct expression is used in the inet family.
quoted
Signed-off-by: Patrick McHardy <redacted>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
 net/netfilter/nft_ct.c |   39 ++++++++++++++++++++++++++++++++++++---
 1 file changed, 36 insertions(+), 3 deletions(-)
quoted
diff --git a/net/netfilter/nft_ct.c b/net/netfilter/nft_ct.c
index 955f4e6..3727a32 100644
--- a/net/netfilter/nft_ct.c
+++ b/net/netfilter/nft_ct.c
[...]
quoted
+static void nft_ct_l3proto_module_put(uint8_t family)
+{
+	if (family == NFPROTO_INET) {
+		nf_ct_l3proto_module_put(NFPROTO_IPV4);
+		nf_ct_l3proto_module_put(NFPROTO_IPV6);
+	} else
+		nf_ct_l3proto_module_put(family);
   According to Documentation/CodingStyle, there should be {} in the
*else* arm, as the other arm of *if* statement has it.
I can see you're looking out for the important stuff. I consistently
used this style in nftables so I'm not going to change it here.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help