[Bug 842] Addition of iptables rule referencing an ipset of the wrong address family does not fail

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Wed Aug 14 15:58:02 CEST 2013


https://bugzilla.netfilter.org/show_bug.cgi?id=842

Jozsef Kadlecsik <kadlec at netfilter.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
                 CC|                            |kadlec at netfilter.org
         Resolution|                            |WONTFIX

--- Comment #2 from Jozsef Kadlecsik <kadlec at netfilter.org> 2013-08-14 15:58:01 CEST ---
That is so because of the "list:set" type, where the member sets can be of any
family type and also the members can be changed anytime. In other words, one
cannot verify the INET family at all.

For the other set types the family checking could be added only by changing the
protocol. If you think this is a serious issue, please reopen the bugreport.

-- 
Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.



More information about the netfilter-buglog mailing list