[Bug 1041] nftables in a container affects the host

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Mon Feb 13 19:29:41 CET 2017


https://bugzilla.netfilter.org/show_bug.cgi?id=1041

--- Comment #2 from Pablo Neira Ayuso <pablo at netfilter.org> ---
For just the record:

4.1 needs this workaround though, we have to request inclusion into -stable.

commit fdab6a4cbd8933092155449ca7253eba973ada14
Author: Eric W. Biederman <ebiederm at xmission.com>
Date:   Fri Jun 19 10:41:21 2015 -0500

    netfilter: nftables: Do not run chains in the wrong network namespace

We got per-netns netfilter hooks since 4.3.

-- 
You are receiving this mail because:
You are watching all bug changes.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.netfilter.org/pipermail/netfilter-buglog/attachments/20170213/a8254e80/attachment.html>


More information about the netfilter-buglog mailing list