[PATCH net] netfilter: xtables: fix a bad copypaste in xt_nflog module

Ignat Korchagin posted 1 patch 1 month, 1 week ago
net/netfilter/xt_NFLOG.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH net] netfilter: xtables: fix a bad copypaste in xt_nflog module
Posted by Ignat Korchagin 1 month, 1 week ago
For the nflog_tg_reg struct under the CONFIG_IP6_NF_IPTABLES switch
family should probably be NFPROTO_IPV6

Fixes: 0bfcb7b71e73 ("netfilter: xtables: avoid NFPROTO_UNSPEC where needed")
Cc: stable@vger.kernel.org
Signed-off-by: Ignat Korchagin <ignat@cloudflare.com>
---
 net/netfilter/xt_NFLOG.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/netfilter/xt_NFLOG.c b/net/netfilter/xt_NFLOG.c
index d80abd6ccaf8..6dcf4bc7e30b 100644
--- a/net/netfilter/xt_NFLOG.c
+++ b/net/netfilter/xt_NFLOG.c
@@ -79,7 +79,7 @@ static struct xt_target nflog_tg_reg[] __read_mostly = {
 	{
 		.name       = "NFLOG",
 		.revision   = 0,
-		.family     = NFPROTO_IPV4,
+		.family     = NFPROTO_IPV6,
 		.checkentry = nflog_tg_check,
 		.destroy    = nflog_tg_destroy,
 		.target     = nflog_tg,
-- 
2.39.5
Re: [PATCH net] netfilter: xtables: fix a bad copypaste in xt_nflog module
Posted by Pablo Neira Ayuso 1 month, 1 week ago
On Fri, Oct 18, 2024 at 05:25:17PM +0100, Ignat Korchagin wrote:
> For the nflog_tg_reg struct under the CONFIG_IP6_NF_IPTABLES switch
> family should probably be NFPROTO_IPV6

Patch is not complete.

I will post a version including mark and TRACE too

> Fixes: 0bfcb7b71e73 ("netfilter: xtables: avoid NFPROTO_UNSPEC where needed")
> Cc: stable@vger.kernel.org
> Signed-off-by: Ignat Korchagin <ignat@cloudflare.com>
> ---
>  net/netfilter/xt_NFLOG.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/net/netfilter/xt_NFLOG.c b/net/netfilter/xt_NFLOG.c
> index d80abd6ccaf8..6dcf4bc7e30b 100644
> --- a/net/netfilter/xt_NFLOG.c
> +++ b/net/netfilter/xt_NFLOG.c
> @@ -79,7 +79,7 @@ static struct xt_target nflog_tg_reg[] __read_mostly = {
>  	{
>  		.name       = "NFLOG",
>  		.revision   = 0,
> -		.family     = NFPROTO_IPV4,
> +		.family     = NFPROTO_IPV6,
>  		.checkentry = nflog_tg_check,
>  		.destroy    = nflog_tg_destroy,
>  		.target     = nflog_tg,
> -- 
> 2.39.5
>