]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
netfilter: xt_socket: enable defrag after all other checks
authorFlorian Westphal <fw@strlen.de>
Sat, 4 Apr 2026 10:12:59 +0000 (12:12 +0200)
committerFlorian Westphal <fw@strlen.de>
Fri, 10 Apr 2026 10:16:26 +0000 (12:16 +0200)
commit542be3fa5aff54210a02954c38f07e53ea9bdafd
tree3071e0197329b392962c6f12f067a53bba844dca
parent24bd5c2679caf8a228d90cafa221da4b47fd6642
netfilter: xt_socket: enable defrag after all other checks

Originally this did not matter because defrag was enabled once per netns
and only disabled again on netns dismantle.  When this got changed I should
have adjusted checkentry to not leave defrag enabled on error.

Fixes: de8c12110a13 ("netfilter: disable defrag once its no longer needed")
Signed-off-by: Florian Westphal <fw@strlen.de>
net/netfilter/xt_socket.c