]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_tables: fix nf_trace always-on with XT_TRACE=n
authorFlorian Westphal <fw@strlen.de>
Sat, 15 Feb 2014 22:48:45 +0000 (23:48 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 17 Feb 2014 10:20:12 +0000 (11:20 +0100)
commitabbc183633e4f0085e886ba56ab4a2da808efa83
tree62451e529b258898c690ca2ad7d0e134745f1a6f
parent9ae8a9262c28d548d59c3a791de443c1f0761ed2
netfilter: nf_tables: fix nf_trace always-on with XT_TRACE=n

When using nftables with CONFIG_NETFILTER_XT_TARGET_TRACE=n, we get
lots of "TRACE: filter:output:policy:1 IN=..." warnings as several
places will leave skb->nf_trace uninitialised.

Unlike iptables tracing functionality is not conditional in nftables,
so always copy/zero nf_trace setting when nftables is enabled.

Move this into __nf_copy() helper.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/linux/skbuff.h
net/core/skbuff.c
net/ipv4/ip_output.c
net/ipv6/ip6_output.c