author | Pablo Neira Ayuso <pablo@netfilter.org> | |
Sat, 21 Mar 2015 18:25:05 +0000 (19:25 +0100) | ||
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | |
Sat, 4 Jul 2015 02:49:05 +0000 (19:49 -0700) | ||
commit | b89c87de3c8836ef14e643ce89684a2a2afb9bb5 | |
tree | 5477fbd262a1857db317832445ffd65ab8f7401b | tree | snapshot (tar.xz tar.gz zip) |
parent | b2e7c364e03f9aa8b11c3b1f30d83e7ed255fe9a | commit | diff |
netfilter: nft_compat: set IP6T_F_PROTO flag if protocol is set
commit 749177ccc74f9c6d0f51bd78a15c652a2134aa11 upstream.
ip6tables extensions check for this flag to restrict match/target to a
given protocol. Without this flag set, SYNPROXY6 returns an error.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Acked-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
commit 749177ccc74f9c6d0f51bd78a15c652a2134aa11 upstream.
ip6tables extensions check for this flag to restrict match/target to a
given protocol. Without this flag set, SYNPROXY6 returns an error.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Acked-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/netfilter/nft_compat.c | diff | blob | history |