From: Mark Andrews Date: Thu, 18 Oct 2007 05:42:03 +0000 (+0000) Subject: Additional changes for: X-Git-Tag: v9.5.0~357 X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=a6237c895b4eedb2ce5a400704d59aa36642ea86;p=thirdparty%2Fbind9.git Additional changes for: 2252. [bug] Fixed errors in sortlist code [RT #17216] --- diff --git a/lib/isccfg/aclconf.c b/lib/isccfg/aclconf.c index bdb4bb0f227..191228e4b56 100644 --- a/lib/isccfg/aclconf.c +++ b/lib/isccfg/aclconf.c @@ -15,7 +15,7 @@ * PERFORMANCE OF THIS SOFTWARE. */ -/* $Id: aclconf.c,v 1.12 2007/10/12 04:17:18 each Exp $ */ +/* $Id: aclconf.c,v 1.13 2007/10/18 05:42:03 marka Exp $ */ #include @@ -239,13 +239,17 @@ cfg_acl_fromconfig(const cfg_obj_t *caml, unsigned int bitlen; cfg_obj_asnetprefix(ce, &addr, &bitlen); + + /* + * If nesting ACLs (nest_level != 0), we negate + * the nestedacl element, not the iptable entry + */ result = dns_iptable_addprefix(iptab, &addr, bitlen, - ISC_TF(!neg)); + ISC_TF(nest_level != 0 || !neg)); if (result != ISC_R_SUCCESS) goto cleanup; if (nest_level != 0) { - /* This prefix is going into a nested acl */ de->type = dns_aclelementtype_nestedacl; de->negative = neg; } else