* Wed Jul 22 2026 Phil Sutter <psutter@redhat.com> [1.0.9-8.el9]
- spec: Update expected test suite results (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for out-of-path call (Phil Sutter) [RHEL-190549]
- tests: monitor: Excercise all syntaxes and variants by default (Phil Sutter) [RHEL-190549]
- tests: monitor: Test JSON echo mode as well (Phil Sutter) [RHEL-190549]
- tests: monitor: Become $PWD agnostic (Phil Sutter) [RHEL-190549]
- tests: monitor: Run in own netns (Phil Sutter) [RHEL-190549]
- tests: monitor: Label diffs to help users (Phil Sutter) [RHEL-190549]
- tests: monitor: Extend testcases a bit (Phil Sutter) [RHEL-190549]
- tests: monitor: enclose device names in quotes (Phil Sutter) [RHEL-190549]
- json: Dump flowtable hook spec only if present (Phil Sutter) [RHEL-190549]
- tests: py: Fix some JSON equivalents (Phil Sutter) [RHEL-190549]
- rule: constify set_is_non_concat_range() (Phil Sutter) [RHEL-190549]
- datatype: don't return a const string from cgroupv2_get_path() (Phil Sutter) [RHEL-190549]
- tests: py: Fix --keep test runner option (Phil Sutter) [RHEL-190549]
- segtree: fix get element command with open intervals (Phil Sutter) [RHEL-190549]
- segtree: replace default case by specific types in get_set_intervals() (Phil Sutter) [RHEL-190549]
- src: remove EXPR_SET_ELEM in range_expr_value_{low,high}() (Phil Sutter) [RHEL-190549]
- segtree: rename set_elem_add() to set_elem_expr_add() (Phil Sutter) [RHEL-190549]
- parser_json: fix map/set type confusion crash in map statement parser (Phil Sutter) [RHEL-190549]
- cache: honor -c/--check for reset commands (Phil Sutter) [RHEL-190549]
- tests: py: osf is ip-only (Phil Sutter) [RHEL-190549]
- tests: py: print the file name as intended (Phil Sutter) [RHEL-190549]
- tests: py: don't use a fixed filename (Phil Sutter) [RHEL-190549]
- mnl: Fix ordering of hooks in 'list hooks' output (Phil Sutter) [RHEL-190549]
- segtree: Fix for variable-sized object may not be initialized (Phil Sutter) [RHEL-190549]
- cache: Filter for table when listing flowtables (Phil Sutter) [RHEL-190549]
- cache: Filter for table when listing sets or maps (Phil Sutter) [RHEL-190549]
- cache: Respect family in all list commands (Phil Sutter) [RHEL-190549]
- cache: Include chains, flowtables and objects in netlink debug output (Phil Sutter) [RHEL-190549]
- cache: Relax chain_cache_dump filter application (Phil Sutter) [RHEL-190549]
- parser_bison: add range check for synproxy wscale (Phil Sutter) [RHEL-190549]
- json: complete multi-statement set element support (Phil Sutter) [RHEL-190549]
- segtree: Fix range aggregation on Big Endian (Phil Sutter) [RHEL-190549]
- mergesort: Align concatenation sort order with Big Endian (Phil Sutter) [RHEL-190549]
- mergesort: Fix sorting of string values (Phil Sutter) [RHEL-190549]
- tests: py: any/tcpopt.t.json: Fix JSON equivalent (Phil Sutter) [RHEL-190549]
- expression: expr_build_udata_recurse should recurse (Phil Sutter) [RHEL-190549]
- expression: propagate key datatype for anonymous sets (Phil Sutter) [RHEL-190549]
- netlink_delinearize: also consider exthdr type when trimming binops (Phil Sutter) [RHEL-190549]
- tcpopt: add symbol table for mptcp suboptions (Phil Sutter) [RHEL-190549]
- monitor: fix memleak in setelem cb (Phil Sutter) [RHEL-190549]
- tests: json_echo: Drop rule handle before multi-add (Phil Sutter) [RHEL-190549]
- rule: skip CMD_OBJ_SETELEMS with no elements after set flush (Phil Sutter) [RHEL-190549]
- doc: libnftables-json: Describe RULESET object (Phil Sutter) [RHEL-190549]
- doc: don't suggest to disable GSO (Phil Sutter) [RHEL-190549]
- tests: py: Implement payload_record() (Phil Sutter) [RHEL-190549]
- tests: py: inet/osf.t: Fix element ordering in JSON equivalents (Phil Sutter) [RHEL-190549]
- tests: py: Do not rely upon '[end]' marker (Phil Sutter) [RHEL-190549]
- tests: py: Fix for using wrong payload path (Phil Sutter) [RHEL-190549]
- tests: py: any/ct.t.json.output: Drop leftover entry (Phil Sutter) [RHEL-190549]
- datatype: Fix boolean type on Big Endian (Phil Sutter) [RHEL-190549]
- optimize: Fix verdict expression comparison (Phil Sutter) [RHEL-190549]
- src: parser_json: fix format string bugs (Phil Sutter) [RHEL-190549]
- doc: fix tcpdump example (Phil Sutter) [RHEL-190549]
- tests: py: objects.t: must use input, not output (Phil Sutter) [RHEL-190549]
- fib: Fix for existence check on Big Endian (Phil Sutter) [RHEL-190549]
- tests: Prepare exit codes for automake (Phil Sutter) [RHEL-190549]
- monitor: Inform JSON printer when reporting an object delete event (Phil Sutter) [RHEL-190549]
- monitor: Recognize flowtable add/del events (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix regex collecting expected echo output (Phil Sutter) [RHEL-190549]
- monitor: Quote device names in chain declarations, too (Phil Sutter) [RHEL-190549]
- mnl: continue on ENOBUFS errors when processing batch (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for flag arrays in JSON output (Phil Sutter) [RHEL-190549]
- mnl: silence compiler warning (Phil Sutter) [RHEL-190549]
- fib: restore JSON output for relational expressions (Phil Sutter) [RHEL-190549]
- src: ensure chain policy evaluation when specified (Phil Sutter) [RHEL-190549]
- segtree: incorrect type when aggregating concatenated set ranges (Phil Sutter) [RHEL-190549]
- json: Do not reduce single-item arrays on output (Phil Sutter) [RHEL-190549]
- tests: py: Fix tests added for 'icmpv6 taddr' support (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from ip/snat.t.payload (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entries from ip6/{ct,meta}.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from ip/snat.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/vxlan.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from inet/tcp.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/gretap.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/gre.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/geneve.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entries since redundant test case removal (Phil Sutter) [RHEL-190549]
- src: netlink: netlink_delinearize_table() may return NULL (Phil Sutter) [RHEL-190549]
- doc: nft.8: Minor NAT STATEMENTS section review (Phil Sutter) [RHEL-190549]
- mnl: Call mnl_attr_nest_end() just once (Phil Sutter) [RHEL-190549]
- evaluate: validate set expression type before accessing flags (Phil Sutter) [RHEL-190549]
- rule: print chain and flowtable devices in quotes (Phil Sutter) [RHEL-190549]
- tests: py: re-enables nft-test.py to load the local nftables.py (Phil Sutter) [RHEL-190549]
- fib: allow to use it in set statements (Phil Sutter) [RHEL-190549]
- fib: allow to check if route exists in maps (Phil Sutter) [RHEL-190549]
- tests: shell: Fix ifname_based_hooks feature check (Phil Sutter) [RHEL-190549]
- json: reject too long interface names (Phil Sutter) [RHEL-190549]
- tests/py: clean up set backend support fallout (Phil Sutter) [RHEL-190549]
- cache: assert name is non-nul when looking up (Phil Sutter) [RHEL-190549]
- parser_bison: only reset by name is supported by now (Phil Sutter) [RHEL-190549]
- rule: skip fuzzy lookup if object name is not available (Phil Sutter) [RHEL-190549]
- parser_bison: allow delete command with map via handle (Phil Sutter) [RHEL-190549]
- debug: include kernel set information on cache fill (Phil Sutter) [RHEL-190549]
- tests/py: prepare for set debug change (Phil Sutter) [RHEL-190549]
- src: BASECHAIN flag no longer implies presence of priority expression (Phil Sutter) [RHEL-190549]
- netlink: Avoid crash upon missing NFTNL_OBJ_CT_TIMEOUT_ARRAY attribute (Phil Sutter) [RHEL-190549]
- tests: py: Properly fix JSON equivalents for netdev/reject.t (Phil Sutter) [RHEL-190549]
- tests: shell: Adjust to ifname-based hooks (Phil Sutter) [RHEL-190549]
- tests: shell: combine dormant flag with netdevice removal (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for single flag array avoidance (Phil Sutter) [RHEL-190549]
- netlink: Do not allocate a bogus flowtable priority expr (Phil Sutter) [RHEL-190549]
- netlink: Fix for potential crash parsing a flowtable (Phil Sutter) [RHEL-190549]
- json: work around fuzzer-induced assert crashes (Phil Sutter) [RHEL-190549]
- json: prevent null deref if chain->policy is not set (Phil Sutter) [RHEL-190549]
- tests: py: fix json single-flag output for fib & synproxy (Phil Sutter) [RHEL-190549]
- tests: shell: check for features not available in 5.4 (Phil Sutter) [RHEL-190549]
- netlink: Avoid potential NULL-ptr deref parsing set elem expressions (Phil Sutter) [RHEL-190549]
- netlink: Catch unknown types when deserializing objects (Phil Sutter) [RHEL-190549]
- json: Introduce json_add_array_new() (Phil Sutter) [RHEL-190549]
- json: Fix for memleak in __binop_expr_json (Phil Sutter) [RHEL-190549]
- json: Accept more than two operands in binary expressions (Phil Sutter) [RHEL-190549]
- json: Print single fib flag as non-array (Phil Sutter) [RHEL-190549]
- tests: shell: Add test case for JSON 'flags' arrays (Phil Sutter) [RHEL-190549]
- json: Print single set flag as non-array (Phil Sutter) [RHEL-190549]
- json: Print single synproxy flags as non-array (Phil Sutter) [RHEL-190549]
- parser_json: Introduce parse_flags_array() (Phil Sutter) [RHEL-190549]
- doc: Fix typo in nat statement 'prefix' description (Phil Sutter) [RHEL-190549]
- netlink: bogus concatenated set ranges with netlink message overrun (Phil Sutter) [RHEL-190549]
- parser_bison: add selector_expr rule to restrict typeof_expr (Phil Sutter) [RHEL-190549]
- optimize: invalidate merge in case of duplicated key in set/map (Phil Sutter) [RHEL-190549]
- evaluate: bail out if ct saddr/daddr dependency cannot be inserted (Phil Sutter) [RHEL-190549]
- parser_json: bail out on malformed statement in set (Phil Sutter) [RHEL-190549]
- parser_json: reject empty jump/goto chain (Phil Sutter) [RHEL-190549]
- parser_json: allow statement stateful statement only in set elements (Phil Sutter) [RHEL-190549]
- cache: prevent possible crash rule filter is NULL (Phil Sutter) [RHEL-190549]
- optimize: expand expression list when merging into concatenation (Phil Sutter) [RHEL-190549]
- cache: don't crash when filter is NULL (Phil Sutter) [RHEL-190549]
- evaluate: only allow stateful statements in set and map definitions (Phil Sutter) [RHEL-190549]
- evaluate: compact STMT_F_STATEFUL checks (Phil Sutter) [RHEL-190549]
- json: don't BUG when asked to list synproxies (Phil Sutter) [RHEL-190549]
- optimize: incorrect comparison for reject statement (Phil Sutter) [RHEL-190549]
- optimize: compact bitmask matching in set/map (Phil Sutter) [RHEL-190549]
- tests: shell: missing ct count elements in new set_stmt test (Phil Sutter) [RHEL-190549]
- evaluate: don't update cache for anonymous chains (Phil Sutter) [RHEL-190549]
- json: make sure timeout list is initialised (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate connlimit grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate last grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate quota grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate limit grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate counter grammar rule for set elements (Phil Sutter) [RHEL-190549]
- tests: shell: extend coverage for set element statements (Phil Sutter) [RHEL-190549]
- evaluate: fix assertion failure with malformed map definitions (Phil Sutter) [RHEL-190549]
- evaluate: don't allow nat map with specified protocol (Phil Sutter) [RHEL-190549]
- parser_bison: reject non-serializeable typeof expressions (Phil Sutter) [RHEL-190549]
- netlink: fix stack buffer overrun when emitting ranged expressions (Phil Sutter) [RHEL-190549]
- src: print set element with multi-word description in single one line (Phil Sutter) [RHEL-190549]
- tests: shell: detach synproxy test (Phil Sutter) [RHEL-190549]
- src: do not merge a set with a erroneous one (Phil Sutter) [RHEL-190549]
- segtree: incomplete output in get element command with maps (Phil Sutter) [RHEL-190549]
- evaluate: release existing datatype when evaluating unary expression (Phil Sutter) [RHEL-190549]
- segtree: fix string data initialisation (Phil Sutter) [RHEL-190549]
- payload: honor inner payload description in payload_expr_cmp() (Phil Sutter) [RHEL-190549]
- payload: return early if dependency is not a payload expression (Phil Sutter) [RHEL-190549]
- evaluate: optimize zero length range (Phil Sutter) [RHEL-190549]
- fib: Change data type of fib oifname to "ifname" (Phil Sutter) [RHEL-190549]
- evaluate: auto-merge is only available for singleton interval sets (Phil Sutter) [RHEL-190549]
- parser_bison: compact and simplify list and reset syntax (Phil Sutter) [RHEL-190549]
- parser_bison: turn redundant ip option type field match into boolean (Phil Sutter) [RHEL-190549]
- datatype: clamp boolean value to 0 and 1 (Phil Sutter) [RHEL-190549]
- tests: shell: delete netdev chain after test (Phil Sutter) [RHEL-190549]
- ipopt: use ipv4 address datatype for address field in ip options (Phil Sutter) [RHEL-190549]
- netlink_delinarize: fix bogus munging of mask value (Phil Sutter) [RHEL-190549]
- evaluate: remove variable shadowing (Phil Sutter) [RHEL-190549]
- intervals: do not merge intervals with different timeout (Phil Sutter) [RHEL-190549]
- src: add EXPR_RANGE_VALUE expression and use it (Phil Sutter) [RHEL-190549]
- intervals: add helper function to set previous element (Phil Sutter) [RHEL-190549]
- parser_bison: fix UaF when reporting table parse error (Phil Sutter) [RHEL-190549]
- intervals: set internal element location with the deletion trigger (Phil Sutter) [RHEL-190549]
- optimize: compare expression length (Phil Sutter) [RHEL-190549]
- tests: py: Fix for storing payload into missing file (Phil Sutter) [RHEL-190549]
- json: Support typeof in set and map types (Phil Sutter) [RHEL-190549]
- json: collapse set element commands from parser (Phil Sutter) [RHEL-190549]
- doc: extend description of fib expression (Phil Sutter) [RHEL-190549]
- tests: monitor: fix up test case breakage (Phil Sutter) [RHEL-190549]
- src: fix extended netlink error reporting with large set elements (Phil Sutter) [RHEL-190549]
- mnl: rename to mnl_seqnum_alloc() to mnl_seqnum_inc() (Phil Sutter) [RHEL-190549]
- mnl: update cmd_add_loc() to take struct nlmsghdr (Phil Sutter) [RHEL-190549]
- rule: netlink attribute offset is uint32_t for struct nlerr_loc (Phil Sutter) [RHEL-190549]
- src: collapse set element commands from parser (Phil Sutter) [RHEL-190549]
- libnftables-json: fix raw payload expression documentation (Phil Sutter) [RHEL-190549]
- cache: initialize filter when fetching implicit chains (Phil Sutter) [RHEL-190549]
- tests: py: fix up udp csum fixup output (Phil Sutter) [RHEL-190549]
- proto: use NFT_PAYLOAD_L4CSUM_PSEUDOHDR flag to mangle UDP checksum (Phil Sutter) [RHEL-190549]
- tests: shell: stabilize packetpath/payload (Phil Sutter) [RHEL-190549]
- libnftables: Zero ctx->vars after freeing it (Phil Sutter) [RHEL-190549]
- cache: position does not require full cache (Phil Sutter) [RHEL-190549]
- cache: relax requirement for replace rule command (Phil Sutter) [RHEL-190549]
- cache: remove full cache requirement when echo flag is set on (Phil Sutter) [RHEL-190549]
- cache: assert filter when calling nft_cache_evaluate() (Phil Sutter) [RHEL-190549]
- cache: consolidate reset command (Phil Sutter) [RHEL-190549]
- cache: add filtering support for objects (Phil Sutter) [RHEL-190549]
- cache: only dump rules for the given table (Phil Sutter) [RHEL-190549]
- cache: accumulate flags in batch (Phil Sutter) [RHEL-190549]
- cache: reset filter for each command (Phil Sutter) [RHEL-190549]
- parser_json: fix several expression memleaks from error path (Phil Sutter) [RHEL-190549]
- parser_json: release buffer returned by json_dumps (Phil Sutter) [RHEL-190549]
- json: Support maps with concatenated data (Phil Sutter) [RHEL-190549]
- parser_json: fix crash in json_parse_set_stmt_list (Phil Sutter) [RHEL-190549]
- parser_bison: allow 0 burst in limit rate byte mode (Phil Sutter) [RHEL-190549]
- datatype: improve error reporting when time unit is not correct (Phil Sutter) [RHEL-190549]
- cache: rule by index requires full cache (Phil Sutter) [RHEL-190549]
- datatype: reject rate in quota statement (Phil Sutter) [RHEL-190549]
- optimize: skip variables in nat statements (Phil Sutter) [RHEL-190549]
- parser_json: use stdin buffer if available (Phil Sutter) [RHEL-190549]
- libnftables: skip useable checks for /dev/stdin (Phil Sutter) [RHEL-190549]
- optimize: clone counter before insertion into set element (Phil Sutter) [RHEL-190549]
- segtree: set on EXPR_F_KERNEL flag for catchall elements in the cache (Phil Sutter) [RHEL-190549]
- evaluate: set on expr->len for catchall set elements (Phil Sutter) [RHEL-190549]
- parser_bison: recursive table declaration in deprecated meter statement (Phil Sutter) [RHEL-190549]
- intervals: fix element deletions with maps (Phil Sutter) [RHEL-190549]
- src: add string preprocessor and use it for log prefix string (Phil Sutter) [RHEL-190549]
- tests: shell: skip ip option tests if kernel does not support it (Phil Sutter) [RHEL-190549]
- cmd: skip variable set elements when collapsing commands (Phil Sutter) [RHEL-190549]
- cmd: provide better hint if chain is already declared with different type/hook/priority (Phil Sutter) [RHEL-190549]
- monitor: too large shift exponent displaying payload expression (Phil Sutter) [RHEL-190549]
- scanner: inet_pton() allows for broader IPv4-Mapped IPv6 addresses (Phil Sutter) [RHEL-190549]
- evaluate: Fix incorrect checking the `base` variable in case of IPV6 (Phil Sutter) [RHEL-190549]
- evaluate: bogus protocol conflicts in vlan with implicit dependencies (Phil Sutter) [RHEL-190549]
- cache: check for NFT_CACHE_REFRESH in current requested cache too (Phil Sutter) [RHEL-190549]
- doc: nft.8: Fix markup in ct expectation synopsis (Phil Sutter) [RHEL-190549]
- mergesort: Avoid accidental set element reordering (Phil Sutter) [RHEL-190549]
- doc: nft.8: Two minor synopsis fixups (Phil Sutter) [RHEL-190549]
- tests: shell: check for reset tcp options support (Phil Sutter) [RHEL-190549]
- tests: shell: payload matching requires egress support (Phil Sutter) [RHEL-190549]
- tests: py: complete icmp and icmpv6 update (Phil Sutter) [RHEL-190549]
- src: disentangle ICMP code types (Phil Sutter) [RHEL-190549]
- evaluate: display "Range negative size" error (Phil Sutter) [RHEL-190549]
- netlink_delinearize: restore binop syntax when listing ruleset for flags (Phil Sutter) [RHEL-190549]
- doc: libnftables-json: Drop invalid ops from match expression (Phil Sutter) [RHEL-190549]
- parser: json: Support for synproxy objects (Phil Sutter) [RHEL-190549]
- tests: py: add payload merging test cases (Phil Sutter) [RHEL-190549]
- nftables: do mot merge payloads on negation (Phil Sutter) [RHEL-190549]
- rule: fix ASAN errors in chain priority to textual names (Phil Sutter) [RHEL-190549]
- parser: compact type/typeof set rules (Phil Sutter) [RHEL-190549]
- parser: compact interval typeof rules (Phil Sutter) [RHEL-190549]
- src: improve error reporting for destroy command (Phil Sutter) [RHEL-190549]
- tests: shell: permit use of host-endian constant values in set lookup keys (Phil Sutter) [RHEL-190549]
- evaluate: permit use of host-endian constant values in set lookup keys (Phil Sutter) [RHEL-190549]
- expression: missing line in describe command with invalid expression (Phil Sutter) [RHEL-190549]
- netlink_delinearize: move concat and value postprocessing to helpers (Phil Sutter) [RHEL-190549]
- evaluate: skip byteorder conversion for selector smaller than 2 bytes (Phil Sutter) [RHEL-190549]
- cache: Optimize caching for 'list tables' command (Phil Sutter) [RHEL-190549]
- evaluate: fix check for unknown in cmd_op_to_name (Phil Sutter) [RHEL-190549]
- evaluate: don't assert on net/transport header conflict (Phil Sutter) [RHEL-190549]
- json: Support sets' auto-merge option (Phil Sutter) [RHEL-190549]
- rule: fix sym refcount assertion (Phil Sutter) [RHEL-190549]
- evaluate: error out when store needs more than one 128bit register of align fixup (Phil Sutter) [RHEL-190549]
- evaluate: do not fetch next expression on runaway number of concatenation components (Phil Sutter) [RHEL-190549]
- evaluate: skip anonymous set optimization for concatenations (Phil Sutter) [RHEL-190549]
- evaluate: add missing range checks for dup,fwd and payload statements (Phil Sutter) [RHEL-190549]
- doc: incorrect datatype description for icmpv6_type and icmpvx_code (Phil Sutter) [RHEL-190549]
- tests: shell: prefer project nft to system-wide nft (Phil Sutter) [RHEL-190549]
- parser_bison: ensure all timeout policy names are released (Phil Sutter) [RHEL-190549]
- netlink: fix stack overflow due to erroneous rounding (Phil Sutter) [RHEL-190549]
- parser_bison: error out on duplicated type/typeof/element keywords (Phil Sutter) [RHEL-190549]
- tests: shell: add test to cover payload transport match and mangle (Phil Sutter) [RHEL-190549]
- evaluate: fix stack overflow with huge priority string (Phil Sutter) [RHEL-190549]
- src: reject large raw payload and concat expressions (Phil Sutter) [RHEL-190549]
- evaluate: exthdr: statement arg must be not be a range (Phil Sutter) [RHEL-190549]
- meta: fix tc classid parsing out-of-bounds access (Phil Sutter) [RHEL-190549]
- parser_bison: close chain scope before chain release (Phil Sutter) [RHEL-190549]
- evaluate: fix bogus assertion failure with boolean datatype (Phil Sutter) [RHEL-190549]
- parser_bison: fix objref statement corruption (Phil Sutter) [RHEL-190549]
- tests: py: missing json output in meta.t with vlan mapping (Phil Sutter) [RHEL-190549]
- evaluate: reset statement length context before evaluating statement (Phil Sutter) [RHEL-190549]
- parser: tcpopt: fix tcp option parsing with NUM + length field (Phil Sutter) [RHEL-190549]
- evaluate: reject set definition with no key (Phil Sutter) [RHEL-190549]
- monitor: add support for concatenated set ranges (Phil Sutter) [RHEL-190549]
- evaluate: disable meta set with ranges (Phil Sutter) [RHEL-190549]
- evaluate: prevent assert when evaluating very large shift values (Phil Sutter) [RHEL-190549]
- evaluate: reject sets with no key (Phil Sutter) [RHEL-190549]
- evaluate: clone unary expression datatype to deal with dynamic datatype (Phil Sutter) [RHEL-190549]
- tests: shell: split nat inet tests (Phil Sutter) [RHEL-190549]
- evaluate: bogus error when adding devices to flowtable (Phil Sutter) [RHEL-190549]
- tests: shell: flush connlimit sets (Phil Sutter) [RHEL-190549]
- tests: shell: adjust add-after-delete flowtable for older kernels (Phil Sutter) [RHEL-190549]
- evaluate: fix rule replacement with anon sets (Phil Sutter) [RHEL-190549]
- tests: shell: skip if kernel does not support flowtable counter (Phil Sutter) [RHEL-190549]
- tests: shell: restore pipapo and chain binding coverage in standalone 30s-stress (Phil Sutter) [RHEL-190549]
- json: fix use after free in table_flags_json() (Phil Sutter) [RHEL-190549]
- src: expand create commands (Phil Sutter) [RHEL-190549]
- tests: shell: split set NAT interval test (Phil Sutter) [RHEL-190549]
- tests: shell: split merge nat optimization in two tests (Phil Sutter) [RHEL-190549]
- netlink: fix buffer size for user data in netlink_delinearize_chain() (Phil Sutter) [RHEL-190549]
- src: remove xfree() and use plain free() (Phil Sutter) [RHEL-190549]
- src: add free_const() and use it instead of xfree() (Phil Sutter) [RHEL-190549]
- evaluate: place byteorder conversion before rshift in payload expressions (Phil Sutter) [RHEL-190549]
- evaluate: reset statement length context only for set mappings (Phil Sutter) [RHEL-190549]
- meta: fix hour decoding when timezone offset is negative (Phil Sutter) [RHEL-190549]
- tproxy: Drop artificial port printing restriction (Phil Sutter) [RHEL-190549]
- tests/shell: fix mount command in "test-wrapper.sh" (Phil Sutter) [RHEL-190549]
- parser_bison: fix length check for ifname in ifname_expr_alloc() (Phil Sutter) [RHEL-190549]
- tests/shell: cover long interface name in "0042chain_variable_0" test (Phil Sutter) [RHEL-190549]
- tests/shell: add missing "elem_opts_compat_0.nodump" file (Phil Sutter) [RHEL-190549]
- parser_bison: Fix for broken compatibility with older dumps (Phil Sutter) [RHEL-190549]
Resolves: RHEL-190549
565 lines
17 KiB
Diff
565 lines
17 KiB
Diff
From 094d220d2fcaae5b67789b58f54d59e7b016657e Mon Sep 17 00:00:00 2001
|
|
From: Phil Sutter <psutter@redhat.com>
|
|
Date: Fri, 17 Jul 2026 11:08:43 +0200
|
|
Subject: [PATCH] src: disentangle ICMP code types
|
|
|
|
JIRA: https://issues.redhat.com/browse/RHEL-190549
|
|
Upstream Status: nftables commit 5fecd2a6ef614eca7b0829e684449ee25982c233
|
|
|
|
commit 5fecd2a6ef614eca7b0829e684449ee25982c233
|
|
Author: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
Date: Tue Apr 2 00:28:24 2024 +0200
|
|
|
|
src: disentangle ICMP code types
|
|
|
|
Currently, ICMP{v4,v6,inet} code datatypes only describe those that are
|
|
supported by the reject statement, but they can also be used for icmp
|
|
code matching. Moreover, ICMP code types go hand-to-hand with ICMP
|
|
types, that is, ICMP code symbols depend on the ICMP type.
|
|
|
|
Thus, the output of:
|
|
|
|
nft describe icmp_code
|
|
|
|
look confusing because that only displays the values that are supported
|
|
by the reject statement.
|
|
|
|
Disentangle this by adding internal datatypes for the reject statement
|
|
to handle the ICMP code symbol conversion to value as well as ruleset
|
|
listing.
|
|
|
|
The existing icmp_code, icmpv6_code and icmpx_code remain in place. For
|
|
backward compatibility, a parser function is defined in case an existing
|
|
ruleset relies on these symbols.
|
|
|
|
As for the manpage, move existing ICMP code tables from the DATA TYPES
|
|
section to the REJECT STATEMENT section, where this really belongs to.
|
|
But the icmp_code and icmpv6_code table stubs remain in the DATA TYPES
|
|
section because that describe that this is an 8-bit integer field.
|
|
|
|
After this patch:
|
|
|
|
# nft describe icmp_code
|
|
datatype icmp_code (icmp code) (basetype integer), 8 bits
|
|
# nft describe icmpv6_code
|
|
datatype icmpv6_code (icmpv6 code) (basetype integer), 8 bits
|
|
# nft describe icmpx_code
|
|
datatype icmpx_code (icmpx code) (basetype integer), 8 bits
|
|
|
|
do not display the symbol table of the reject statement anymore.
|
|
|
|
icmpx_code_type is not used anymore, but keep it in place for backward
|
|
compatibility reasons.
|
|
|
|
And update tests/shell accordingly.
|
|
|
|
Fixes: 5fdd0b6a0600 ("nft: complete reject support")
|
|
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
|
|
Signed-off-by: Phil Sutter <psutter@redhat.com>
|
|
---
|
|
doc/data-types.txt | 68 -----------------------------------
|
|
doc/statements.txt | 74 ++++++++++++++++++++++++++++++---------
|
|
include/datatype.h | 5 +++
|
|
src/datatype.c | 71 +++++++++++++++++++++++++++++++++----
|
|
src/netlink_delinearize.c | 10 +++---
|
|
src/parser_bison.y | 12 +++----
|
|
src/parser_json.c | 6 ++--
|
|
tests/py/ip/icmp.t | 6 ++--
|
|
tests/py/ip6/icmpv6.t | 8 ++---
|
|
9 files changed, 147 insertions(+), 113 deletions(-)
|
|
|
|
diff --git a/doc/data-types.txt b/doc/data-types.txt
|
|
index e5ee91a..6c0e2f9 100644
|
|
--- a/doc/data-types.txt
|
|
+++ b/doc/data-types.txt
|
|
@@ -242,28 +242,6 @@ integer
|
|
|
|
The ICMP Code type is used to conveniently specify the ICMP header's code field.
|
|
|
|
-.Keywords may be used when specifying the ICMP code
|
|
-[options="header"]
|
|
-|==================
|
|
-|Keyword | Value
|
|
-|net-unreachable |
|
|
-0
|
|
-|host-unreachable |
|
|
-1
|
|
-|prot-unreachable|
|
|
-2
|
|
-|port-unreachable|
|
|
-3
|
|
-|frag-needed|
|
|
-4
|
|
-|net-prohibited|
|
|
-9
|
|
-|host-prohibited|
|
|
-10
|
|
-|admin-prohibited|
|
|
-13
|
|
-|===================
|
|
-
|
|
ICMPV6 TYPE TYPE
|
|
~~~~~~~~~~~~~~~~
|
|
[options="header"]
|
|
@@ -340,52 +318,6 @@ integer
|
|
|
|
The ICMPv6 Code type is used to conveniently specify the ICMPv6 header's code field.
|
|
|
|
-.keywords may be used when specifying the ICMPv6 code
|
|
-[options="header"]
|
|
-|==================
|
|
-|Keyword |Value
|
|
-|no-route|
|
|
-0
|
|
-|admin-prohibited|
|
|
-1
|
|
-|addr-unreachable|
|
|
-3
|
|
-|port-unreachable|
|
|
-4
|
|
-|policy-fail|
|
|
-5
|
|
-|reject-route|
|
|
-6
|
|
-|==================
|
|
-
|
|
-ICMPVX CODE TYPE
|
|
-~~~~~~~~~~~~~~~~
|
|
-[options="header"]
|
|
-|==================
|
|
-|Name | Keyword | Size | Base type
|
|
-|ICMPvX Code |
|
|
-icmpx_code |
|
|
-8 bit |
|
|
-integer
|
|
-|===================
|
|
-
|
|
-The ICMPvX Code type abstraction is a set of values which overlap between ICMP
|
|
-and ICMPv6 Code types to be used from the inet family.
|
|
-
|
|
-.keywords may be used when specifying the ICMPvX code
|
|
-[options="header"]
|
|
-|==================
|
|
-|Keyword |Value
|
|
-|no-route|
|
|
-0
|
|
-|port-unreachable|
|
|
-1
|
|
-|host-unreachable|
|
|
-2
|
|
-|admin-prohibited|
|
|
-3
|
|
-|=================
|
|
-
|
|
CONNTRACK TYPES
|
|
~~~~~~~~~~~~~~~
|
|
|
|
diff --git a/doc/statements.txt b/doc/statements.txt
|
|
index c29a2ff..834adb2 100644
|
|
--- a/doc/statements.txt
|
|
+++ b/doc/statements.txt
|
|
@@ -164,9 +164,9 @@ REJECT STATEMENT
|
|
____
|
|
*reject* [ *with* 'REJECT_WITH' ]
|
|
|
|
-'REJECT_WITH' := *icmp* 'icmp_code' |
|
|
- *icmpv6* 'icmpv6_code' |
|
|
- *icmpx* 'icmpx_code' |
|
|
+'REJECT_WITH' := *icmp* 'icmp_reject_code' |
|
|
+ *icmpv6* 'icmpv6_reject_code' |
|
|
+ *icmpx* 'icmpx_reject_code' |
|
|
*tcp reset*
|
|
____
|
|
|
|
@@ -177,24 +177,64 @@ using the *input*,
|
|
*forward* or *output* hooks, and user-defined chains which are only called from
|
|
those chains.
|
|
|
|
-.different ICMP reject variants are meant for use in different table families
|
|
+.Keywords may be used to reject when specifying the ICMP code
|
|
[options="header"]
|
|
|==================
|
|
-|Variant |Family | Type
|
|
-|icmp|
|
|
-ip|
|
|
-icmp_code
|
|
-|icmpv6|
|
|
-ip6|
|
|
-icmpv6_code
|
|
-|icmpx|
|
|
-inet|
|
|
-icmpx_code
|
|
+|Keyword | Value
|
|
+|net-unreachable |
|
|
+0
|
|
+|host-unreachable |
|
|
+1
|
|
+|prot-unreachable|
|
|
+2
|
|
+|port-unreachable|
|
|
+3
|
|
+|frag-needed|
|
|
+4
|
|
+|net-prohibited|
|
|
+9
|
|
+|host-prohibited|
|
|
+10
|
|
+|admin-prohibited|
|
|
+13
|
|
+|===================
|
|
+
|
|
+.keywords may be used to reject when specifying the ICMPv6 code
|
|
+[options="header"]
|
|
|==================
|
|
+|Keyword |Value
|
|
+|no-route|
|
|
+0
|
|
+|admin-prohibited|
|
|
+1
|
|
+|addr-unreachable|
|
|
+3
|
|
+|port-unreachable|
|
|
+4
|
|
+|policy-fail|
|
|
+5
|
|
+|reject-route|
|
|
+6
|
|
+|==================
|
|
+
|
|
+The ICMPvX Code type abstraction is a set of values which overlap between ICMP
|
|
+and ICMPv6 Code types to be used from the inet family.
|
|
+
|
|
+.keywords may be used when specifying the ICMPvX code
|
|
+[options="header"]
|
|
+|==================
|
|
+|Keyword |Value
|
|
+|no-route|
|
|
+0
|
|
+|port-unreachable|
|
|
+1
|
|
+|host-unreachable|
|
|
+2
|
|
+|admin-prohibited|
|
|
+3
|
|
+|=================
|
|
|
|
-For a description of the different types and a list of supported keywords refer
|
|
-to DATA TYPES section above. The common default reject value is
|
|
-*port-unreachable*. +
|
|
+The common default ICMP code to reject is *port-unreachable*.
|
|
|
|
Note that in bridge family, reject statement is only allowed in base chains
|
|
which hook into input or prerouting.
|
|
diff --git a/include/datatype.h b/include/datatype.h
|
|
index 09a7894..68e12d5 100644
|
|
--- a/include/datatype.h
|
|
+++ b/include/datatype.h
|
|
@@ -280,6 +280,11 @@ extern const struct datatype priority_type;
|
|
extern const struct datatype policy_type;
|
|
extern const struct datatype cgroupv2_type;
|
|
|
|
+/* private datatypes for reject statement. */
|
|
+extern const struct datatype reject_icmp_code_type;
|
|
+extern const struct datatype reject_icmpv6_code_type;
|
|
+extern const struct datatype reject_icmpx_code_type;
|
|
+
|
|
void inet_service_type_print(const struct expr *expr, struct output_ctx *octx);
|
|
|
|
extern const struct datatype *concat_type_alloc(uint32_t type);
|
|
diff --git a/src/datatype.c b/src/datatype.c
|
|
index a92f41d..46d77eb 100644
|
|
--- a/src/datatype.c
|
|
+++ b/src/datatype.c
|
|
@@ -978,6 +978,7 @@ const struct datatype mark_type = {
|
|
.flags = DTYPE_F_PREFIX,
|
|
};
|
|
|
|
+/* symbol table for private datatypes for reject statement. */
|
|
static const struct symbol_table icmp_code_tbl = {
|
|
.base = BASE_DECIMAL,
|
|
.symbols = {
|
|
@@ -993,16 +994,17 @@ static const struct symbol_table icmp_code_tbl = {
|
|
},
|
|
};
|
|
|
|
-const struct datatype icmp_code_type = {
|
|
- .type = TYPE_ICMP_CODE,
|
|
+/* private datatype for reject statement. */
|
|
+const struct datatype reject_icmp_code_type = {
|
|
.name = "icmp_code",
|
|
- .desc = "icmp code",
|
|
+ .desc = "reject icmp code",
|
|
.size = BITS_PER_BYTE,
|
|
.byteorder = BYTEORDER_BIG_ENDIAN,
|
|
.basetype = &integer_type,
|
|
.sym_tbl = &icmp_code_tbl,
|
|
};
|
|
|
|
+/* symbol table for private datatypes for reject statement. */
|
|
static const struct symbol_table icmpv6_code_tbl = {
|
|
.base = BASE_DECIMAL,
|
|
.symbols = {
|
|
@@ -1016,16 +1018,17 @@ static const struct symbol_table icmpv6_code_tbl = {
|
|
},
|
|
};
|
|
|
|
-const struct datatype icmpv6_code_type = {
|
|
- .type = TYPE_ICMPV6_CODE,
|
|
+/* private datatype for reject statement. */
|
|
+const struct datatype reject_icmpv6_code_type = {
|
|
.name = "icmpv6_code",
|
|
- .desc = "icmpv6 code",
|
|
+ .desc = "reject icmpv6 code",
|
|
.size = BITS_PER_BYTE,
|
|
.byteorder = BYTEORDER_BIG_ENDIAN,
|
|
.basetype = &integer_type,
|
|
.sym_tbl = &icmpv6_code_tbl,
|
|
};
|
|
|
|
+/* symbol table for private datatypes for reject statement. */
|
|
static const struct symbol_table icmpx_code_tbl = {
|
|
.base = BASE_DECIMAL,
|
|
.symbols = {
|
|
@@ -1037,6 +1040,60 @@ static const struct symbol_table icmpx_code_tbl = {
|
|
},
|
|
};
|
|
|
|
+/* private datatype for reject statement. */
|
|
+const struct datatype reject_icmpx_code_type = {
|
|
+ .name = "icmpx_code",
|
|
+ .desc = "reject icmpx code",
|
|
+ .size = BITS_PER_BYTE,
|
|
+ .byteorder = BYTEORDER_BIG_ENDIAN,
|
|
+ .basetype = &integer_type,
|
|
+ .sym_tbl = &icmpx_code_tbl,
|
|
+};
|
|
+
|
|
+/* Backward compatible parser for the reject statement. */
|
|
+static struct error_record *icmp_code_parse(struct parse_ctx *ctx,
|
|
+ const struct expr *sym,
|
|
+ struct expr **res)
|
|
+{
|
|
+ return symbolic_constant_parse(ctx, sym, &icmp_code_tbl, res);
|
|
+}
|
|
+
|
|
+const struct datatype icmp_code_type = {
|
|
+ .type = TYPE_ICMP_CODE,
|
|
+ .name = "icmp_code",
|
|
+ .desc = "icmp code",
|
|
+ .size = BITS_PER_BYTE,
|
|
+ .byteorder = BYTEORDER_BIG_ENDIAN,
|
|
+ .basetype = &integer_type,
|
|
+ .parse = icmp_code_parse,
|
|
+};
|
|
+
|
|
+/* Backward compatible parser for the reject statement. */
|
|
+static struct error_record *icmpv6_code_parse(struct parse_ctx *ctx,
|
|
+ const struct expr *sym,
|
|
+ struct expr **res)
|
|
+{
|
|
+ return symbolic_constant_parse(ctx, sym, &icmpv6_code_tbl, res);
|
|
+}
|
|
+
|
|
+const struct datatype icmpv6_code_type = {
|
|
+ .type = TYPE_ICMPV6_CODE,
|
|
+ .name = "icmpv6_code",
|
|
+ .desc = "icmpv6 code",
|
|
+ .size = BITS_PER_BYTE,
|
|
+ .byteorder = BYTEORDER_BIG_ENDIAN,
|
|
+ .basetype = &integer_type,
|
|
+ .parse = icmpv6_code_parse,
|
|
+};
|
|
+
|
|
+/* Backward compatible parser for the reject statement. */
|
|
+static struct error_record *icmpx_code_parse(struct parse_ctx *ctx,
|
|
+ const struct expr *sym,
|
|
+ struct expr **res)
|
|
+{
|
|
+ return symbolic_constant_parse(ctx, sym, &icmpx_code_tbl, res);
|
|
+}
|
|
+
|
|
const struct datatype icmpx_code_type = {
|
|
.type = TYPE_ICMPX_CODE,
|
|
.name = "icmpx_code",
|
|
@@ -1044,7 +1101,7 @@ const struct datatype icmpx_code_type = {
|
|
.size = BITS_PER_BYTE,
|
|
.byteorder = BYTEORDER_BIG_ENDIAN,
|
|
.basetype = &integer_type,
|
|
- .sym_tbl = &icmpx_code_tbl,
|
|
+ .parse = icmpx_code_parse,
|
|
};
|
|
|
|
void time_print(uint64_t ms, struct output_ctx *octx)
|
|
diff --git a/src/netlink_delinearize.c b/src/netlink_delinearize.c
|
|
index 405a065..1af0278 100644
|
|
--- a/src/netlink_delinearize.c
|
|
+++ b/src/netlink_delinearize.c
|
|
@@ -2930,7 +2930,7 @@ static void stmt_reject_postprocess(struct rule_pp_ctx *rctx)
|
|
switch (dl->pctx.family) {
|
|
case NFPROTO_IPV4:
|
|
stmt->reject.family = dl->pctx.family;
|
|
- datatype_set(stmt->reject.expr, &icmp_code_type);
|
|
+ datatype_set(stmt->reject.expr, &reject_icmp_code_type);
|
|
if (stmt->reject.type == NFT_REJECT_TCP_RST &&
|
|
payload_dependency_exists(&dl->pdctx,
|
|
PROTO_BASE_TRANSPORT_HDR))
|
|
@@ -2939,7 +2939,7 @@ static void stmt_reject_postprocess(struct rule_pp_ctx *rctx)
|
|
break;
|
|
case NFPROTO_IPV6:
|
|
stmt->reject.family = dl->pctx.family;
|
|
- datatype_set(stmt->reject.expr, &icmpv6_code_type);
|
|
+ datatype_set(stmt->reject.expr, &reject_icmpv6_code_type);
|
|
if (stmt->reject.type == NFT_REJECT_TCP_RST &&
|
|
payload_dependency_exists(&dl->pdctx,
|
|
PROTO_BASE_TRANSPORT_HDR))
|
|
@@ -2950,7 +2950,7 @@ static void stmt_reject_postprocess(struct rule_pp_ctx *rctx)
|
|
case NFPROTO_BRIDGE:
|
|
case NFPROTO_NETDEV:
|
|
if (stmt->reject.type == NFT_REJECT_ICMPX_UNREACH) {
|
|
- datatype_set(stmt->reject.expr, &icmpx_code_type);
|
|
+ datatype_set(stmt->reject.expr, &reject_icmpx_code_type);
|
|
break;
|
|
}
|
|
|
|
@@ -2966,12 +2966,12 @@ static void stmt_reject_postprocess(struct rule_pp_ctx *rctx)
|
|
case NFPROTO_IPV4: /* INET */
|
|
case __constant_htons(ETH_P_IP): /* BRIDGE, NETDEV */
|
|
stmt->reject.family = NFPROTO_IPV4;
|
|
- datatype_set(stmt->reject.expr, &icmp_code_type);
|
|
+ datatype_set(stmt->reject.expr, &reject_icmp_code_type);
|
|
break;
|
|
case NFPROTO_IPV6: /* INET */
|
|
case __constant_htons(ETH_P_IPV6): /* BRIDGE, NETDEV */
|
|
stmt->reject.family = NFPROTO_IPV6;
|
|
- datatype_set(stmt->reject.expr, &icmpv6_code_type);
|
|
+ datatype_set(stmt->reject.expr, &reject_icmpv6_code_type);
|
|
break;
|
|
default:
|
|
break;
|
|
diff --git a/src/parser_bison.y b/src/parser_bison.y
|
|
index 23b64ce..e3ac2fb 100644
|
|
--- a/src/parser_bison.y
|
|
+++ b/src/parser_bison.y
|
|
@@ -3715,40 +3715,40 @@ reject_opts : /* empty */
|
|
$<stmt>0->reject.family = NFPROTO_IPV4;
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
$<stmt>0->reject.expr = $4;
|
|
- datatype_set($<stmt>0->reject.expr, &icmp_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmp_code_type);
|
|
}
|
|
| WITH ICMP reject_with_expr
|
|
{
|
|
$<stmt>0->reject.family = NFPROTO_IPV4;
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
$<stmt>0->reject.expr = $3;
|
|
- datatype_set($<stmt>0->reject.expr, &icmp_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmp_code_type);
|
|
}
|
|
| WITH ICMP6 TYPE reject_with_expr close_scope_type close_scope_icmp
|
|
{
|
|
$<stmt>0->reject.family = NFPROTO_IPV6;
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
$<stmt>0->reject.expr = $4;
|
|
- datatype_set($<stmt>0->reject.expr, &icmpv6_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmpv6_code_type);
|
|
}
|
|
| WITH ICMP6 reject_with_expr
|
|
{
|
|
$<stmt>0->reject.family = NFPROTO_IPV6;
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
$<stmt>0->reject.expr = $3;
|
|
- datatype_set($<stmt>0->reject.expr, &icmpv6_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmpv6_code_type);
|
|
}
|
|
| WITH ICMPX TYPE reject_with_expr close_scope_type
|
|
{
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMPX_UNREACH;
|
|
$<stmt>0->reject.expr = $4;
|
|
- datatype_set($<stmt>0->reject.expr, &icmpx_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmpx_code_type);
|
|
}
|
|
| WITH ICMPX reject_with_expr
|
|
{
|
|
$<stmt>0->reject.type = NFT_REJECT_ICMPX_UNREACH;
|
|
$<stmt>0->reject.expr = $3;
|
|
- datatype_set($<stmt>0->reject.expr, &icmpx_code_type);
|
|
+ datatype_set($<stmt>0->reject.expr, &reject_icmpx_code_type);
|
|
}
|
|
| WITH TCP close_scope_tcp RESET close_scope_reset
|
|
{
|
|
diff --git a/src/parser_json.c b/src/parser_json.c
|
|
index b8ed848..25483b1 100644
|
|
--- a/src/parser_json.c
|
|
+++ b/src/parser_json.c
|
|
@@ -2318,17 +2318,17 @@ static struct stmt *json_parse_reject_stmt(struct json_ctx *ctx,
|
|
stmt->reject.icmp_code = 0;
|
|
} else if (!strcmp(type, "icmpx")) {
|
|
stmt->reject.type = NFT_REJECT_ICMPX_UNREACH;
|
|
- dtype = &icmpx_code_type;
|
|
+ dtype = &reject_icmpx_code_type;
|
|
stmt->reject.icmp_code = 0;
|
|
} else if (!strcmp(type, "icmp")) {
|
|
stmt->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
stmt->reject.family = NFPROTO_IPV4;
|
|
- dtype = &icmp_code_type;
|
|
+ dtype = &reject_icmp_code_type;
|
|
stmt->reject.icmp_code = 0;
|
|
} else if (!strcmp(type, "icmpv6")) {
|
|
stmt->reject.type = NFT_REJECT_ICMP_UNREACH;
|
|
stmt->reject.family = NFPROTO_IPV6;
|
|
- dtype = &icmpv6_code_type;
|
|
+ dtype = &reject_icmpv6_code_type;
|
|
stmt->reject.icmp_code = 0;
|
|
}
|
|
}
|
|
diff --git a/tests/py/ip/icmp.t b/tests/py/ip/icmp.t
|
|
index 7ddf8b3..226c339 100644
|
|
--- a/tests/py/ip/icmp.t
|
|
+++ b/tests/py/ip/icmp.t
|
|
@@ -26,8 +26,8 @@ icmp code 111 accept;ok
|
|
icmp code != 111 accept;ok
|
|
icmp code 33-55;ok
|
|
icmp code != 33-55;ok
|
|
-icmp code { 2, 4, 54, 33, 56};ok;icmp code { prot-unreachable, frag-needed, 33, 54, 56}
|
|
-icmp code != { prot-unreachable, frag-needed, 33, 54, 56};ok
|
|
+icmp code { 2, 4, 54, 33, 56};ok
|
|
+icmp code != { prot-unreachable, frag-needed, 33, 54, 56};ok;icmp code != { 2, 4, 33, 54, 56}
|
|
|
|
icmp checksum 12343 accept;ok
|
|
icmp checksum != 12343 accept;ok
|
|
@@ -73,5 +73,5 @@ icmp gateway != { 33, 55, 67, 88};ok
|
|
icmp gateway != 34;ok
|
|
icmp gateway != { 333, 334};ok
|
|
|
|
-icmp code 1 icmp type 2;ok;icmp type 2 icmp code host-unreachable
|
|
+icmp code 1 icmp type 2;ok;icmp type 2 icmp code 1
|
|
icmp code != 1 icmp type 2 icmp mtu 5;fail
|
|
diff --git a/tests/py/ip6/icmpv6.t b/tests/py/ip6/icmpv6.t
|
|
index 35dad2b..7632bfd 100644
|
|
--- a/tests/py/ip6/icmpv6.t
|
|
+++ b/tests/py/ip6/icmpv6.t
|
|
@@ -28,10 +28,10 @@ icmpv6 type {router-renumbering, mld-listener-done, time-exceeded, nd-router-sol
|
|
icmpv6 type {mld-listener-query, time-exceeded, nd-router-advert} accept;ok
|
|
icmpv6 type != {mld-listener-query, time-exceeded, nd-router-advert} accept;ok
|
|
|
|
-icmpv6 code 4;ok;icmpv6 code port-unreachable
|
|
+icmpv6 code 4;ok
|
|
icmpv6 code 3-66;ok
|
|
-icmpv6 code {5, 6, 7} accept;ok;icmpv6 code {policy-fail, reject-route, 7} accept
|
|
-icmpv6 code != {policy-fail, reject-route, 7} accept;ok
|
|
+icmpv6 code {5, 6, 7} accept;ok
|
|
+icmpv6 code != {policy-fail, reject-route, 7} accept;ok;icmpv6 code != {5, 6, 7} accept
|
|
|
|
icmpv6 checksum 2222 log;ok
|
|
icmpv6 checksum != 2222 log;ok
|
|
@@ -84,7 +84,7 @@ icmpv6 max-delay != 33-45;ok
|
|
icmpv6 max-delay {33, 55, 67, 88};ok
|
|
icmpv6 max-delay != {33, 55, 67, 88};ok
|
|
|
|
-icmpv6 type parameter-problem icmpv6 code no-route;ok
|
|
+icmpv6 type parameter-problem icmpv6 code 0;ok
|
|
|
|
icmpv6 type mld-listener-query icmpv6 taddr 2001:db8::133;ok
|
|
icmpv6 type nd-neighbor-solicit icmpv6 taddr 2001:db8::133;ok
|