]> git.ipfire.org Git - thirdparty/iptables.git/commit
Revert "nft: prefer payload to ttl/hl module"/'meta pkttype' match.
authorFlorian Westphal <fw@strlen.de>
Thu, 22 Sep 2022 14:14:51 +0000 (16:14 +0200)
committerFlorian Westphal <fw@strlen.de>
Thu, 22 Sep 2022 14:16:14 +0000 (16:16 +0200)
commitdccccdff1f6d37a2f1fdbc4ef22f2a97bf0cf1a6
tree0eb9c315eaa25bda9a92621cd020ea59fb371150
parent32efb4ffc33ae874b3f26f3380e2184ad6ceb26f
Revert "nft: prefer payload to ttl/hl module"/'meta pkttype' match.

This reverts commit 8acaccf69c22fb195a0b88e28489792304728245.
This reverts commit 793caef9076cceb24336b6cbb8f55107de49f269.

As per ongoing discussion, keep the dissection side but keep using
nft_compat mode for now until we've figured out how to handle
backwards compatibility with older iptables-nft binaries dumping
the ruleset.

Furthermore, "nft: prefer native 'meta pkttype' instead of xt match"
broke ebtables: it has its own, incompatible pkttype match and needs
special handling.

Signed-off-by: Florian Westphal <fw@strlen.de>
iptables/nft.c