Message ID | 20131025150436.GA7536@localhost |
---|---|
State | Accepted |
Delegated to: | Jozsef Kadlecsik |
Headers | show |
On Fri, 25 Oct 2013 17:04:36 +0200, Pablo Neira Ayuso wrote: > reject support was never finished. Please, find enclosed patches for > libnftables and nft. That was fast, thanks! Seems to work. Tested-by: Jiri Benc <jbenc@redhat.com> > ICMP code support is still missing, perhaps you want to investigate > how to add it to nft. It should be a small follow up patch. Yes, that would be useful. I may look into that but no promises as of when. Feel free to beat me. Jiri
On Fri, Oct 25, 2013 at 05:46:51PM +0200, Jiri Benc wrote: > On Fri, 25 Oct 2013 17:04:36 +0200, Pablo Neira Ayuso wrote: > > reject support was never finished. Please, find enclosed patches for > > libnftables and nft. > > That was fast, thanks! Seems to work. > > Tested-by: Jiri Benc <jbenc@redhat.com> Applied, thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
From 41fbf2fd89a166bb3bb8d7d11bf790aa6011fcd1 Mon Sep 17 00:00:00 2001 From: Pablo Neira Ayuso <pablo@netfilter.org> Date: Fri, 25 Oct 2013 17:01:58 +0200 Subject: [PATCH nft] netlink_linearize: finish reject support This patch finishes the reject support. Reported-by: Jiri Benc <jbenc@redhat.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> --- src/netlink_linearize.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/netlink_linearize.c b/src/netlink_linearize.c index c1d1a9a..96ffe68 100644 --- a/src/netlink_linearize.c +++ b/src/netlink_linearize.c @@ -692,7 +692,9 @@ static void netlink_gen_reject_stmt(struct netlink_linearize_ctx *ctx, { struct nft_rule_expr *nle; - nle = alloc_nft_expr(NULL); + nle = alloc_nft_expr("reject"); + nft_rule_expr_set_u32(nle, NFT_EXPR_REJECT_TYPE, stmt->reject.type); + nft_rule_expr_set_u8(nle, NFT_EXPR_REJECT_CODE, 0); nft_rule_add_expr(ctx->nlr, nle); } -- 1.7.10.4