both of these rules succeed, but they should fail instead.
nft removes the ip6 nexthdr' clause, but this is not correct, it is an
explicit test for the ipv6 nexthdr value.
Implicit dependencies use meta l4proto to skip extension headers
(if any), ipv6 nexthdr does not.
Signed-off-by: Florian Westphal <fw@strlen.de>
ip protocol icmp icmp type echo-request;ok;icmp type echo-request
icmp type echo-request;ok
-ip6 nexthdr icmpv6 icmpv6 type echo-request;ok;icmpv6 type echo-request
+ip6 nexthdr icmpv6 icmpv6 type echo-request;ok;ip6 nexthdr 58 icmpv6 type echo-request
icmpv6 type echo-request;ok
ip protocol icmp icmp type echo-request;ok;icmp type echo-request
icmp type echo-request;ok
-ip6 nexthdr icmpv6 icmpv6 type echo-request;ok;icmpv6 type echo-request
+ip6 nexthdr icmpv6 icmpv6 type echo-request;ok;ip6 nexthdr 58 icmpv6 type echo-request
icmpv6 type echo-request;ok