Commit 0461c1bf authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso Committed by Greg Kroah-Hartman
Browse files

UPSTREAM: netfilter: xtables: fix typo causing some targets not to load on IPv6



[ Upstream commit 306ed172 ]

- There is no NFPROTO_IPV6 family for mark and NFLOG.
- TRACE is also missing module autoload with NFPROTO_IPV6.

This results in ip6tables failing to restore a ruleset. This issue has been
reported by several users providing incomplete patches.

Very similar to Ilya Katsnelson's patch including a missing chunk in the
TRACE extension.

Fixes: 0bfcb7b7 ("netfilter: xtables: avoid NFPROTO_UNSPEC where needed")
Reported-by: default avatarIgnat Korchagin <ignat@cloudflare.com>
Reported-by: default avatarIlya Katsnelson <me@0upti.me>
Reported-by: default avatarKrzysztof Olędzki <ole@ans.pl>
Change-Id: Ib8a151eb5e1b6f0d2d3efd6ca971cb8efab9b9e5
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
(cherry picked from commit 90baa455)
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@google.com>
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent 20ae3488
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment