As expires is stateful information. This patch removes expire
information from list stateless ruleset. With nft -s option, the
ruleset will be as following.
table ip firewall {
set host {
type ipv4_addr
flags timeout
elements = { 10.0.0.2 timeout 10m }
}
}
Signed-off-by: Varsha Rao <rvarsha016@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
printf(" timeout ");
time_print(expr->timeout / 1000);
}
- if (expr->expiration) {
+ if (!stateless_output && expr->expiration) {
printf(" expires ");
time_print(expr->expiration / 1000);
}