[Bug 932] New: TOS: An Invert mask in TOS
bugzilla-daemon at netfilter.org
bugzilla-daemon at netfilter.org
Tue May 13 14:25:03 CEST 2014
https://bugzilla.netfilter.org/show_bug.cgi?id=932
Summary: TOS: An Invert mask in TOS
Product: nftables
Version: unspecified
Platform: x86_64
OS/Version: Debian GNU/Linux
Status: NEW
Severity: normal
Priority: P5
Component: nft
AssignedTo: pablo at netfilter.org
ReportedBy: anarey at gmail.com
Estimated Hours: 0.0
Without show some error message, you can add a rule using invert option with
flags, but after, you can not show the table. Here some examples of this bug.
$ sudo nft add rule ip test3 input ip tos and 0x04 == 0x02 counter accept
$ sudo nft list table test3
table ip test3 {
chain input {
ip tos & 4 == 2 counter packets 0 bytes 0 accept
}
}
[Here, all is ok]
$ sudo nft add rule ip test3 input ip tos and 0x04 != 0x02 counter accept
$ sudo nft list table test3
[ERROR: The table is not shown]
The last commit in Pablo git tree of kernel is "40e6442 netfilter: x_tables:
allow to use cgroup match for LOCAL_IN nf hooks"
The last commit in libmnl repo is "090a842 examples: use mnl_socket_setsockopt"
The last commit in libnftnl repo is "57107c2 common: fix unconditional output
of event wrapping stuff"
The last commit in nftables repo is "aefa9bf expression: Fix inconsistent
output in set"
--
Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.
More information about the netfilter-buglog
mailing list