]> git.ipfire.org Git - thirdparty/iptables.git/commit
nft: fix inversion of built-in selectors
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 18 Nov 2013 12:50:21 +0000 (13:50 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 30 Dec 2013 22:50:53 +0000 (23:50 +0100)
commitee595bc702ca80f72c522406f6a06ba7c31eb8df
tree9c20cb433358f68cdff0abd555d502cc70c86650
parent009bb1ae47f76fc538e0d6365448687f27d0f015
nft: fix inversion of built-in selectors

(0ab045f xtables: fix missing ipt_entry for MASQUERADE target) broke
inversion of built-in selectors, such as -s, -d, etc.

We need to refresh the invflags if -p is used or set it for first
time if -p is not used, otherwise inversion is ignored.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
iptables/nft-ipv4.c
iptables/nft-ipv6.c