bugzilla-daemon at netfilter.org
2013-Apr-21 14:48 UTC
[Bug 812] addrtype with limit-iface-in in ip6tables/nat/PREROUTING messes up the route cache
https://bugzilla.netfilter.org/show_bug.cgi?id=812 Florian Westphal <fw at strlen.de> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |fw at strlen.de --- Comment #1 from Florian Westphal <fw at strlen.de> 2013-04-21 16:48:04 CEST --- Haven't been able to reproduce this so far, but the issue surely is caused by the fact that, when --limit-in is specified we call into the ipv6 route output function while passing the incoming interface as output interface. -- Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching all bug changes.
bugzilla-daemon at netfilter.org
2013-Apr-24 21:42 UTC
[Bug 812] addrtype with limit-iface-in in ip6tables/nat/PREROUTING messes up the route cache
https://bugzilla.netfilter.org/show_bug.cgi?id=812 --- Comment #2 from Florian Westphal <fw at strlen.de> 2013-04-24 23:42:00 CEST --- (In reply to comment #1)> Haven't been able to reproduce this so far, but the issue surely > is caused by the fact that, when --limit-in is specified we call > into the ipv6 route output function while passing > the incoming interface as output interface.I can reproduce this, and I have a fix but it introduces unwanted dependency on ipv6 module. I'll have to think about how to best avoid it. One possibility would be to revert the ipt_addrtype -> xt_addrtype rename and move the ipv6 specific parts to ip6t_addrtype module. -- Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching all bug changes.
bugzilla-daemon at netfilter.org
2013-May-05 09:32 UTC
[Bug 812] addrtype with limit-iface-in in ip6tables/nat/PREROUTING messes up the route cache
https://bugzilla.netfilter.org/show_bug.cgi?id=812 --- Comment #3 from Florian Westphal <fw at strlen.de> 2013-05-05 11:32:35 CEST --- i am currently testing http://git.breakpoint.cc/cgit.cgi/fw/nf-next.git/commit/?h=addrtype_2&id=3b30d692a351237f73b37b218f5310c5dc29cec0 but this change is a bit intrusive, unfortunately. -- Configure bugmail: https://bugzilla.netfilter.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching all bug changes.
Maybe Matching Threads
- [Bug 812] addrtype with limit-iface-in in ip6tables/nat/PREROUTING messes up the route cache
- [Bug 812] New: addrtype with limit-iface-in in ip6tables/nat/PREROUTING messes up the route cache
- [Bug 1015] ip6tables-save and "-p all" or no specification of protocol.
- [Bug 1186] New: ip6tables-restore not passing useful error messages from ip6tables
- [Bug 745] New: [addrtype]addrtype can't match src-type BROADCAST packets