* Wed Jul 22 2026 Phil Sutter <psutter@redhat.com> [1.0.9-8.el9]
- spec: Update expected test suite results (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for out-of-path call (Phil Sutter) [RHEL-190549]
- tests: monitor: Excercise all syntaxes and variants by default (Phil Sutter) [RHEL-190549]
- tests: monitor: Test JSON echo mode as well (Phil Sutter) [RHEL-190549]
- tests: monitor: Become $PWD agnostic (Phil Sutter) [RHEL-190549]
- tests: monitor: Run in own netns (Phil Sutter) [RHEL-190549]
- tests: monitor: Label diffs to help users (Phil Sutter) [RHEL-190549]
- tests: monitor: Extend testcases a bit (Phil Sutter) [RHEL-190549]
- tests: monitor: enclose device names in quotes (Phil Sutter) [RHEL-190549]
- json: Dump flowtable hook spec only if present (Phil Sutter) [RHEL-190549]
- tests: py: Fix some JSON equivalents (Phil Sutter) [RHEL-190549]
- rule: constify set_is_non_concat_range() (Phil Sutter) [RHEL-190549]
- datatype: don't return a const string from cgroupv2_get_path() (Phil Sutter) [RHEL-190549]
- tests: py: Fix --keep test runner option (Phil Sutter) [RHEL-190549]
- segtree: fix get element command with open intervals (Phil Sutter) [RHEL-190549]
- segtree: replace default case by specific types in get_set_intervals() (Phil Sutter) [RHEL-190549]
- src: remove EXPR_SET_ELEM in range_expr_value_{low,high}() (Phil Sutter) [RHEL-190549]
- segtree: rename set_elem_add() to set_elem_expr_add() (Phil Sutter) [RHEL-190549]
- parser_json: fix map/set type confusion crash in map statement parser (Phil Sutter) [RHEL-190549]
- cache: honor -c/--check for reset commands (Phil Sutter) [RHEL-190549]
- tests: py: osf is ip-only (Phil Sutter) [RHEL-190549]
- tests: py: print the file name as intended (Phil Sutter) [RHEL-190549]
- tests: py: don't use a fixed filename (Phil Sutter) [RHEL-190549]
- mnl: Fix ordering of hooks in 'list hooks' output (Phil Sutter) [RHEL-190549]
- segtree: Fix for variable-sized object may not be initialized (Phil Sutter) [RHEL-190549]
- cache: Filter for table when listing flowtables (Phil Sutter) [RHEL-190549]
- cache: Filter for table when listing sets or maps (Phil Sutter) [RHEL-190549]
- cache: Respect family in all list commands (Phil Sutter) [RHEL-190549]
- cache: Include chains, flowtables and objects in netlink debug output (Phil Sutter) [RHEL-190549]
- cache: Relax chain_cache_dump filter application (Phil Sutter) [RHEL-190549]
- parser_bison: add range check for synproxy wscale (Phil Sutter) [RHEL-190549]
- json: complete multi-statement set element support (Phil Sutter) [RHEL-190549]
- segtree: Fix range aggregation on Big Endian (Phil Sutter) [RHEL-190549]
- mergesort: Align concatenation sort order with Big Endian (Phil Sutter) [RHEL-190549]
- mergesort: Fix sorting of string values (Phil Sutter) [RHEL-190549]
- tests: py: any/tcpopt.t.json: Fix JSON equivalent (Phil Sutter) [RHEL-190549]
- expression: expr_build_udata_recurse should recurse (Phil Sutter) [RHEL-190549]
- expression: propagate key datatype for anonymous sets (Phil Sutter) [RHEL-190549]
- netlink_delinearize: also consider exthdr type when trimming binops (Phil Sutter) [RHEL-190549]
- tcpopt: add symbol table for mptcp suboptions (Phil Sutter) [RHEL-190549]
- monitor: fix memleak in setelem cb (Phil Sutter) [RHEL-190549]
- tests: json_echo: Drop rule handle before multi-add (Phil Sutter) [RHEL-190549]
- rule: skip CMD_OBJ_SETELEMS with no elements after set flush (Phil Sutter) [RHEL-190549]
- doc: libnftables-json: Describe RULESET object (Phil Sutter) [RHEL-190549]
- doc: don't suggest to disable GSO (Phil Sutter) [RHEL-190549]
- tests: py: Implement payload_record() (Phil Sutter) [RHEL-190549]
- tests: py: inet/osf.t: Fix element ordering in JSON equivalents (Phil Sutter) [RHEL-190549]
- tests: py: Do not rely upon '[end]' marker (Phil Sutter) [RHEL-190549]
- tests: py: Fix for using wrong payload path (Phil Sutter) [RHEL-190549]
- tests: py: any/ct.t.json.output: Drop leftover entry (Phil Sutter) [RHEL-190549]
- datatype: Fix boolean type on Big Endian (Phil Sutter) [RHEL-190549]
- optimize: Fix verdict expression comparison (Phil Sutter) [RHEL-190549]
- src: parser_json: fix format string bugs (Phil Sutter) [RHEL-190549]
- doc: fix tcpdump example (Phil Sutter) [RHEL-190549]
- tests: py: objects.t: must use input, not output (Phil Sutter) [RHEL-190549]
- fib: Fix for existence check on Big Endian (Phil Sutter) [RHEL-190549]
- tests: Prepare exit codes for automake (Phil Sutter) [RHEL-190549]
- monitor: Inform JSON printer when reporting an object delete event (Phil Sutter) [RHEL-190549]
- monitor: Recognize flowtable add/del events (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix regex collecting expected echo output (Phil Sutter) [RHEL-190549]
- monitor: Quote device names in chain declarations, too (Phil Sutter) [RHEL-190549]
- mnl: continue on ENOBUFS errors when processing batch (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for flag arrays in JSON output (Phil Sutter) [RHEL-190549]
- mnl: silence compiler warning (Phil Sutter) [RHEL-190549]
- fib: restore JSON output for relational expressions (Phil Sutter) [RHEL-190549]
- src: ensure chain policy evaluation when specified (Phil Sutter) [RHEL-190549]
- segtree: incorrect type when aggregating concatenated set ranges (Phil Sutter) [RHEL-190549]
- json: Do not reduce single-item arrays on output (Phil Sutter) [RHEL-190549]
- tests: py: Fix tests added for 'icmpv6 taddr' support (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from ip/snat.t.payload (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entries from ip6/{ct,meta}.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from ip/snat.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/vxlan.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entry from inet/tcp.t.json (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/gretap.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/gre.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop duplicate test from inet/geneve.t (Phil Sutter) [RHEL-190549]
- tests: py: Drop stale entries since redundant test case removal (Phil Sutter) [RHEL-190549]
- src: netlink: netlink_delinearize_table() may return NULL (Phil Sutter) [RHEL-190549]
- doc: nft.8: Minor NAT STATEMENTS section review (Phil Sutter) [RHEL-190549]
- mnl: Call mnl_attr_nest_end() just once (Phil Sutter) [RHEL-190549]
- evaluate: validate set expression type before accessing flags (Phil Sutter) [RHEL-190549]
- rule: print chain and flowtable devices in quotes (Phil Sutter) [RHEL-190549]
- tests: py: re-enables nft-test.py to load the local nftables.py (Phil Sutter) [RHEL-190549]
- fib: allow to use it in set statements (Phil Sutter) [RHEL-190549]
- fib: allow to check if route exists in maps (Phil Sutter) [RHEL-190549]
- tests: shell: Fix ifname_based_hooks feature check (Phil Sutter) [RHEL-190549]
- json: reject too long interface names (Phil Sutter) [RHEL-190549]
- tests/py: clean up set backend support fallout (Phil Sutter) [RHEL-190549]
- cache: assert name is non-nul when looking up (Phil Sutter) [RHEL-190549]
- parser_bison: only reset by name is supported by now (Phil Sutter) [RHEL-190549]
- rule: skip fuzzy lookup if object name is not available (Phil Sutter) [RHEL-190549]
- parser_bison: allow delete command with map via handle (Phil Sutter) [RHEL-190549]
- debug: include kernel set information on cache fill (Phil Sutter) [RHEL-190549]
- tests/py: prepare for set debug change (Phil Sutter) [RHEL-190549]
- src: BASECHAIN flag no longer implies presence of priority expression (Phil Sutter) [RHEL-190549]
- netlink: Avoid crash upon missing NFTNL_OBJ_CT_TIMEOUT_ARRAY attribute (Phil Sutter) [RHEL-190549]
- tests: py: Properly fix JSON equivalents for netdev/reject.t (Phil Sutter) [RHEL-190549]
- tests: shell: Adjust to ifname-based hooks (Phil Sutter) [RHEL-190549]
- tests: shell: combine dormant flag with netdevice removal (Phil Sutter) [RHEL-190549]
- tests: monitor: Fix for single flag array avoidance (Phil Sutter) [RHEL-190549]
- netlink: Do not allocate a bogus flowtable priority expr (Phil Sutter) [RHEL-190549]
- netlink: Fix for potential crash parsing a flowtable (Phil Sutter) [RHEL-190549]
- json: work around fuzzer-induced assert crashes (Phil Sutter) [RHEL-190549]
- json: prevent null deref if chain->policy is not set (Phil Sutter) [RHEL-190549]
- tests: py: fix json single-flag output for fib & synproxy (Phil Sutter) [RHEL-190549]
- tests: shell: check for features not available in 5.4 (Phil Sutter) [RHEL-190549]
- netlink: Avoid potential NULL-ptr deref parsing set elem expressions (Phil Sutter) [RHEL-190549]
- netlink: Catch unknown types when deserializing objects (Phil Sutter) [RHEL-190549]
- json: Introduce json_add_array_new() (Phil Sutter) [RHEL-190549]
- json: Fix for memleak in __binop_expr_json (Phil Sutter) [RHEL-190549]
- json: Accept more than two operands in binary expressions (Phil Sutter) [RHEL-190549]
- json: Print single fib flag as non-array (Phil Sutter) [RHEL-190549]
- tests: shell: Add test case for JSON 'flags' arrays (Phil Sutter) [RHEL-190549]
- json: Print single set flag as non-array (Phil Sutter) [RHEL-190549]
- json: Print single synproxy flags as non-array (Phil Sutter) [RHEL-190549]
- parser_json: Introduce parse_flags_array() (Phil Sutter) [RHEL-190549]
- doc: Fix typo in nat statement 'prefix' description (Phil Sutter) [RHEL-190549]
- netlink: bogus concatenated set ranges with netlink message overrun (Phil Sutter) [RHEL-190549]
- parser_bison: add selector_expr rule to restrict typeof_expr (Phil Sutter) [RHEL-190549]
- optimize: invalidate merge in case of duplicated key in set/map (Phil Sutter) [RHEL-190549]
- evaluate: bail out if ct saddr/daddr dependency cannot be inserted (Phil Sutter) [RHEL-190549]
- parser_json: bail out on malformed statement in set (Phil Sutter) [RHEL-190549]
- parser_json: reject empty jump/goto chain (Phil Sutter) [RHEL-190549]
- parser_json: allow statement stateful statement only in set elements (Phil Sutter) [RHEL-190549]
- cache: prevent possible crash rule filter is NULL (Phil Sutter) [RHEL-190549]
- optimize: expand expression list when merging into concatenation (Phil Sutter) [RHEL-190549]
- cache: don't crash when filter is NULL (Phil Sutter) [RHEL-190549]
- evaluate: only allow stateful statements in set and map definitions (Phil Sutter) [RHEL-190549]
- evaluate: compact STMT_F_STATEFUL checks (Phil Sutter) [RHEL-190549]
- json: don't BUG when asked to list synproxies (Phil Sutter) [RHEL-190549]
- optimize: incorrect comparison for reject statement (Phil Sutter) [RHEL-190549]
- optimize: compact bitmask matching in set/map (Phil Sutter) [RHEL-190549]
- tests: shell: missing ct count elements in new set_stmt test (Phil Sutter) [RHEL-190549]
- evaluate: don't update cache for anonymous chains (Phil Sutter) [RHEL-190549]
- json: make sure timeout list is initialised (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate connlimit grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate last grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate quota grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate limit grammar rule for set elements (Phil Sutter) [RHEL-190549]
- parser_bison: consolidate counter grammar rule for set elements (Phil Sutter) [RHEL-190549]
- tests: shell: extend coverage for set element statements (Phil Sutter) [RHEL-190549]
- evaluate: fix assertion failure with malformed map definitions (Phil Sutter) [RHEL-190549]
- evaluate: don't allow nat map with specified protocol (Phil Sutter) [RHEL-190549]
- parser_bison: reject non-serializeable typeof expressions (Phil Sutter) [RHEL-190549]
- netlink: fix stack buffer overrun when emitting ranged expressions (Phil Sutter) [RHEL-190549]
- src: print set element with multi-word description in single one line (Phil Sutter) [RHEL-190549]
- tests: shell: detach synproxy test (Phil Sutter) [RHEL-190549]
- src: do not merge a set with a erroneous one (Phil Sutter) [RHEL-190549]
- segtree: incomplete output in get element command with maps (Phil Sutter) [RHEL-190549]
- evaluate: release existing datatype when evaluating unary expression (Phil Sutter) [RHEL-190549]
- segtree: fix string data initialisation (Phil Sutter) [RHEL-190549]
- payload: honor inner payload description in payload_expr_cmp() (Phil Sutter) [RHEL-190549]
- payload: return early if dependency is not a payload expression (Phil Sutter) [RHEL-190549]
- evaluate: optimize zero length range (Phil Sutter) [RHEL-190549]
- fib: Change data type of fib oifname to "ifname" (Phil Sutter) [RHEL-190549]
- evaluate: auto-merge is only available for singleton interval sets (Phil Sutter) [RHEL-190549]
- parser_bison: compact and simplify list and reset syntax (Phil Sutter) [RHEL-190549]
- parser_bison: turn redundant ip option type field match into boolean (Phil Sutter) [RHEL-190549]
- datatype: clamp boolean value to 0 and 1 (Phil Sutter) [RHEL-190549]
- tests: shell: delete netdev chain after test (Phil Sutter) [RHEL-190549]
- ipopt: use ipv4 address datatype for address field in ip options (Phil Sutter) [RHEL-190549]
- netlink_delinarize: fix bogus munging of mask value (Phil Sutter) [RHEL-190549]
- evaluate: remove variable shadowing (Phil Sutter) [RHEL-190549]
- intervals: do not merge intervals with different timeout (Phil Sutter) [RHEL-190549]
- src: add EXPR_RANGE_VALUE expression and use it (Phil Sutter) [RHEL-190549]
- intervals: add helper function to set previous element (Phil Sutter) [RHEL-190549]
- parser_bison: fix UaF when reporting table parse error (Phil Sutter) [RHEL-190549]
- intervals: set internal element location with the deletion trigger (Phil Sutter) [RHEL-190549]
- optimize: compare expression length (Phil Sutter) [RHEL-190549]
- tests: py: Fix for storing payload into missing file (Phil Sutter) [RHEL-190549]
- json: Support typeof in set and map types (Phil Sutter) [RHEL-190549]
- json: collapse set element commands from parser (Phil Sutter) [RHEL-190549]
- doc: extend description of fib expression (Phil Sutter) [RHEL-190549]
- tests: monitor: fix up test case breakage (Phil Sutter) [RHEL-190549]
- src: fix extended netlink error reporting with large set elements (Phil Sutter) [RHEL-190549]
- mnl: rename to mnl_seqnum_alloc() to mnl_seqnum_inc() (Phil Sutter) [RHEL-190549]
- mnl: update cmd_add_loc() to take struct nlmsghdr (Phil Sutter) [RHEL-190549]
- rule: netlink attribute offset is uint32_t for struct nlerr_loc (Phil Sutter) [RHEL-190549]
- src: collapse set element commands from parser (Phil Sutter) [RHEL-190549]
- libnftables-json: fix raw payload expression documentation (Phil Sutter) [RHEL-190549]
- cache: initialize filter when fetching implicit chains (Phil Sutter) [RHEL-190549]
- tests: py: fix up udp csum fixup output (Phil Sutter) [RHEL-190549]
- proto: use NFT_PAYLOAD_L4CSUM_PSEUDOHDR flag to mangle UDP checksum (Phil Sutter) [RHEL-190549]
- tests: shell: stabilize packetpath/payload (Phil Sutter) [RHEL-190549]
- libnftables: Zero ctx->vars after freeing it (Phil Sutter) [RHEL-190549]
- cache: position does not require full cache (Phil Sutter) [RHEL-190549]
- cache: relax requirement for replace rule command (Phil Sutter) [RHEL-190549]
- cache: remove full cache requirement when echo flag is set on (Phil Sutter) [RHEL-190549]
- cache: assert filter when calling nft_cache_evaluate() (Phil Sutter) [RHEL-190549]
- cache: consolidate reset command (Phil Sutter) [RHEL-190549]
- cache: add filtering support for objects (Phil Sutter) [RHEL-190549]
- cache: only dump rules for the given table (Phil Sutter) [RHEL-190549]
- cache: accumulate flags in batch (Phil Sutter) [RHEL-190549]
- cache: reset filter for each command (Phil Sutter) [RHEL-190549]
- parser_json: fix several expression memleaks from error path (Phil Sutter) [RHEL-190549]
- parser_json: release buffer returned by json_dumps (Phil Sutter) [RHEL-190549]
- json: Support maps with concatenated data (Phil Sutter) [RHEL-190549]
- parser_json: fix crash in json_parse_set_stmt_list (Phil Sutter) [RHEL-190549]
- parser_bison: allow 0 burst in limit rate byte mode (Phil Sutter) [RHEL-190549]
- datatype: improve error reporting when time unit is not correct (Phil Sutter) [RHEL-190549]
- cache: rule by index requires full cache (Phil Sutter) [RHEL-190549]
- datatype: reject rate in quota statement (Phil Sutter) [RHEL-190549]
- optimize: skip variables in nat statements (Phil Sutter) [RHEL-190549]
- parser_json: use stdin buffer if available (Phil Sutter) [RHEL-190549]
- libnftables: skip useable checks for /dev/stdin (Phil Sutter) [RHEL-190549]
- optimize: clone counter before insertion into set element (Phil Sutter) [RHEL-190549]
- segtree: set on EXPR_F_KERNEL flag for catchall elements in the cache (Phil Sutter) [RHEL-190549]
- evaluate: set on expr->len for catchall set elements (Phil Sutter) [RHEL-190549]
- parser_bison: recursive table declaration in deprecated meter statement (Phil Sutter) [RHEL-190549]
- intervals: fix element deletions with maps (Phil Sutter) [RHEL-190549]
- src: add string preprocessor and use it for log prefix string (Phil Sutter) [RHEL-190549]
- tests: shell: skip ip option tests if kernel does not support it (Phil Sutter) [RHEL-190549]
- cmd: skip variable set elements when collapsing commands (Phil Sutter) [RHEL-190549]
- cmd: provide better hint if chain is already declared with different type/hook/priority (Phil Sutter) [RHEL-190549]
- monitor: too large shift exponent displaying payload expression (Phil Sutter) [RHEL-190549]
- scanner: inet_pton() allows for broader IPv4-Mapped IPv6 addresses (Phil Sutter) [RHEL-190549]
- evaluate: Fix incorrect checking the `base` variable in case of IPV6 (Phil Sutter) [RHEL-190549]
- evaluate: bogus protocol conflicts in vlan with implicit dependencies (Phil Sutter) [RHEL-190549]
- cache: check for NFT_CACHE_REFRESH in current requested cache too (Phil Sutter) [RHEL-190549]
- doc: nft.8: Fix markup in ct expectation synopsis (Phil Sutter) [RHEL-190549]
- mergesort: Avoid accidental set element reordering (Phil Sutter) [RHEL-190549]
- doc: nft.8: Two minor synopsis fixups (Phil Sutter) [RHEL-190549]
- tests: shell: check for reset tcp options support (Phil Sutter) [RHEL-190549]
- tests: shell: payload matching requires egress support (Phil Sutter) [RHEL-190549]
- tests: py: complete icmp and icmpv6 update (Phil Sutter) [RHEL-190549]
- src: disentangle ICMP code types (Phil Sutter) [RHEL-190549]
- evaluate: display "Range negative size" error (Phil Sutter) [RHEL-190549]
- netlink_delinearize: restore binop syntax when listing ruleset for flags (Phil Sutter) [RHEL-190549]
- doc: libnftables-json: Drop invalid ops from match expression (Phil Sutter) [RHEL-190549]
- parser: json: Support for synproxy objects (Phil Sutter) [RHEL-190549]
- tests: py: add payload merging test cases (Phil Sutter) [RHEL-190549]
- nftables: do mot merge payloads on negation (Phil Sutter) [RHEL-190549]
- rule: fix ASAN errors in chain priority to textual names (Phil Sutter) [RHEL-190549]
- parser: compact type/typeof set rules (Phil Sutter) [RHEL-190549]
- parser: compact interval typeof rules (Phil Sutter) [RHEL-190549]
- src: improve error reporting for destroy command (Phil Sutter) [RHEL-190549]
- tests: shell: permit use of host-endian constant values in set lookup keys (Phil Sutter) [RHEL-190549]
- evaluate: permit use of host-endian constant values in set lookup keys (Phil Sutter) [RHEL-190549]
- expression: missing line in describe command with invalid expression (Phil Sutter) [RHEL-190549]
- netlink_delinearize: move concat and value postprocessing to helpers (Phil Sutter) [RHEL-190549]
- evaluate: skip byteorder conversion for selector smaller than 2 bytes (Phil Sutter) [RHEL-190549]
- cache: Optimize caching for 'list tables' command (Phil Sutter) [RHEL-190549]
- evaluate: fix check for unknown in cmd_op_to_name (Phil Sutter) [RHEL-190549]
- evaluate: don't assert on net/transport header conflict (Phil Sutter) [RHEL-190549]
- json: Support sets' auto-merge option (Phil Sutter) [RHEL-190549]
- rule: fix sym refcount assertion (Phil Sutter) [RHEL-190549]
- evaluate: error out when store needs more than one 128bit register of align fixup (Phil Sutter) [RHEL-190549]
- evaluate: do not fetch next expression on runaway number of concatenation components (Phil Sutter) [RHEL-190549]
- evaluate: skip anonymous set optimization for concatenations (Phil Sutter) [RHEL-190549]
- evaluate: add missing range checks for dup,fwd and payload statements (Phil Sutter) [RHEL-190549]
- doc: incorrect datatype description for icmpv6_type and icmpvx_code (Phil Sutter) [RHEL-190549]
- tests: shell: prefer project nft to system-wide nft (Phil Sutter) [RHEL-190549]
- parser_bison: ensure all timeout policy names are released (Phil Sutter) [RHEL-190549]
- netlink: fix stack overflow due to erroneous rounding (Phil Sutter) [RHEL-190549]
- parser_bison: error out on duplicated type/typeof/element keywords (Phil Sutter) [RHEL-190549]
- tests: shell: add test to cover payload transport match and mangle (Phil Sutter) [RHEL-190549]
- evaluate: fix stack overflow with huge priority string (Phil Sutter) [RHEL-190549]
- src: reject large raw payload and concat expressions (Phil Sutter) [RHEL-190549]
- evaluate: exthdr: statement arg must be not be a range (Phil Sutter) [RHEL-190549]
- meta: fix tc classid parsing out-of-bounds access (Phil Sutter) [RHEL-190549]
- parser_bison: close chain scope before chain release (Phil Sutter) [RHEL-190549]
- evaluate: fix bogus assertion failure with boolean datatype (Phil Sutter) [RHEL-190549]
- parser_bison: fix objref statement corruption (Phil Sutter) [RHEL-190549]
- tests: py: missing json output in meta.t with vlan mapping (Phil Sutter) [RHEL-190549]
- evaluate: reset statement length context before evaluating statement (Phil Sutter) [RHEL-190549]
- parser: tcpopt: fix tcp option parsing with NUM + length field (Phil Sutter) [RHEL-190549]
- evaluate: reject set definition with no key (Phil Sutter) [RHEL-190549]
- monitor: add support for concatenated set ranges (Phil Sutter) [RHEL-190549]
- evaluate: disable meta set with ranges (Phil Sutter) [RHEL-190549]
- evaluate: prevent assert when evaluating very large shift values (Phil Sutter) [RHEL-190549]
- evaluate: reject sets with no key (Phil Sutter) [RHEL-190549]
- evaluate: clone unary expression datatype to deal with dynamic datatype (Phil Sutter) [RHEL-190549]
- tests: shell: split nat inet tests (Phil Sutter) [RHEL-190549]
- evaluate: bogus error when adding devices to flowtable (Phil Sutter) [RHEL-190549]
- tests: shell: flush connlimit sets (Phil Sutter) [RHEL-190549]
- tests: shell: adjust add-after-delete flowtable for older kernels (Phil Sutter) [RHEL-190549]
- evaluate: fix rule replacement with anon sets (Phil Sutter) [RHEL-190549]
- tests: shell: skip if kernel does not support flowtable counter (Phil Sutter) [RHEL-190549]
- tests: shell: restore pipapo and chain binding coverage in standalone 30s-stress (Phil Sutter) [RHEL-190549]
- json: fix use after free in table_flags_json() (Phil Sutter) [RHEL-190549]
- src: expand create commands (Phil Sutter) [RHEL-190549]
- tests: shell: split set NAT interval test (Phil Sutter) [RHEL-190549]
- tests: shell: split merge nat optimization in two tests (Phil Sutter) [RHEL-190549]
- netlink: fix buffer size for user data in netlink_delinearize_chain() (Phil Sutter) [RHEL-190549]
- src: remove xfree() and use plain free() (Phil Sutter) [RHEL-190549]
- src: add free_const() and use it instead of xfree() (Phil Sutter) [RHEL-190549]
- evaluate: place byteorder conversion before rshift in payload expressions (Phil Sutter) [RHEL-190549]
- evaluate: reset statement length context only for set mappings (Phil Sutter) [RHEL-190549]
- meta: fix hour decoding when timezone offset is negative (Phil Sutter) [RHEL-190549]
- tproxy: Drop artificial port printing restriction (Phil Sutter) [RHEL-190549]
- tests/shell: fix mount command in "test-wrapper.sh" (Phil Sutter) [RHEL-190549]
- parser_bison: fix length check for ifname in ifname_expr_alloc() (Phil Sutter) [RHEL-190549]
- tests/shell: cover long interface name in "0042chain_variable_0" test (Phil Sutter) [RHEL-190549]
- tests/shell: add missing "elem_opts_compat_0.nodump" file (Phil Sutter) [RHEL-190549]
- parser_bison: Fix for broken compatibility with older dumps (Phil Sutter) [RHEL-190549]
Resolves: RHEL-190549
529 lines
16 KiB
Diff
529 lines
16 KiB
Diff
From 7677fd4e2273487c86f5f00eed92bcaa0ae03ddc Mon Sep 17 00:00:00 2001
|
|
From: Phil Sutter <psutter@redhat.com>
|
|
Date: Fri, 17 Jul 2026 11:10:09 +0200
|
|
Subject: [PATCH] cache: consolidate reset command
|
|
|
|
JIRA: https://issues.redhat.com/browse/RHEL-190549
|
|
Upstream Status: nftables commit dbff26bfba8336c485a270509440e94bc1240d08
|
|
|
|
commit dbff26bfba8336c485a270509440e94bc1240d08
|
|
Author: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
Date: Mon Aug 26 00:41:42 2024 +0200
|
|
|
|
cache: consolidate reset command
|
|
|
|
Reset command does not utilize the cache infrastructure.
|
|
|
|
This implicitly fixes a crash with anonymous sets because elements are
|
|
not fetched. I initially tried to fix it by toggling the missing cache
|
|
flags, but then ASAN reports memleaks.
|
|
|
|
To address these issues relies on Phil's list filtering infrastructure
|
|
which updates is expanded to accomodate filtering requirements of the
|
|
reset commands, such as 'reset table ip' where only the family is sent
|
|
to the kernel.
|
|
|
|
After this update, tests/shell reports a few inconsistencies between
|
|
reset and list commands:
|
|
|
|
- reset rules chain t c2
|
|
|
|
display sets, but it should only list the given chain.
|
|
|
|
- reset rules table t
|
|
reset rules ip
|
|
|
|
do not list elements in the set. In both cases, these are fully
|
|
listing a given table and family, elements should be included.
|
|
|
|
The consolidation also ensures list and reset will not differ.
|
|
|
|
A few more notes:
|
|
|
|
- CMD_OBJ_TABLE is used for:
|
|
|
|
rules family table
|
|
|
|
from the parser, due to the lack of a better enum, same applies to
|
|
CMD_OBJ_CHAIN.
|
|
|
|
- CMD_OBJ_ELEMENTS still does not use the cache, but same occurs in
|
|
the CMD_GET command case which needs to be consolidated.
|
|
|
|
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1763
|
|
Fixes: 83e0f4402fb7 ("Implement 'reset {set,map,element}' commands")
|
|
Fixes: 1694df2de79f ("Implement 'reset rule' and 'reset rules' commands")
|
|
Tested-by: Eric Garver <eric@garver.life>
|
|
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
|
|
|
|
Signed-off-by: Phil Sutter <psutter@redhat.com>
|
|
---
|
|
include/cache.h | 10 ++-
|
|
include/netlink.h | 5 --
|
|
src/cache.c | 81 +++++++++++++------
|
|
src/evaluate.c | 2 +
|
|
src/mnl.c | 7 +-
|
|
src/netlink.c | 78 ------------------
|
|
src/parser_bison.y | 8 +-
|
|
src/rule.c | 48 +----------
|
|
.../testcases/rule_management/0011reset_0 | 10 +--
|
|
9 files changed, 78 insertions(+), 171 deletions(-)
|
|
|
|
diff --git a/include/cache.h b/include/cache.h
|
|
index e47dc88..4cf7d31 100644
|
|
--- a/include/cache.h
|
|
+++ b/include/cache.h
|
|
@@ -65,6 +65,12 @@ struct nft_cache_filter {
|
|
struct {
|
|
struct list_head head;
|
|
} obj[NFT_CACHE_HSIZE];
|
|
+
|
|
+ struct {
|
|
+ bool obj;
|
|
+ bool rule;
|
|
+ bool elem;
|
|
+ } reset;
|
|
};
|
|
|
|
struct nft_cache;
|
|
@@ -150,8 +156,4 @@ struct netlink_ctx;
|
|
void nft_chain_cache_update(struct netlink_ctx *ctx, struct table *table,
|
|
const char *chain);
|
|
|
|
-int rule_cache_dump(struct netlink_ctx *ctx, const struct handle *h,
|
|
- const struct nft_cache_filter *filter,
|
|
- bool dump, bool reset);
|
|
-
|
|
#endif /* _NFT_CACHE_H_ */
|
|
diff --git a/include/netlink.h b/include/netlink.h
|
|
index 2ce4b39..80e18ee 100644
|
|
--- a/include/netlink.h
|
|
+++ b/include/netlink.h
|
|
@@ -176,8 +176,6 @@ extern int netlink_delinearize_setelem(struct nftnl_set_elem *nlse,
|
|
struct nft_cache *cache);
|
|
|
|
extern int netlink_list_objs(struct netlink_ctx *ctx, const struct handle *h);
|
|
-extern int netlink_reset_objs(struct netlink_ctx *ctx, const struct cmd *cmd,
|
|
- uint32_t type, bool dump);
|
|
extern struct obj *netlink_delinearize_obj(struct netlink_ctx *ctx,
|
|
struct nftnl_obj *nlo);
|
|
|
|
@@ -186,9 +184,6 @@ extern int netlink_list_flowtables(struct netlink_ctx *ctx,
|
|
extern struct flowtable *netlink_delinearize_flowtable(struct netlink_ctx *ctx,
|
|
struct nftnl_flowtable *nlo);
|
|
|
|
-extern int netlink_reset_rules(struct netlink_ctx *ctx, const struct cmd *cmd,
|
|
- bool dump);
|
|
-
|
|
extern void netlink_dump_chain(const struct nftnl_chain *nlc,
|
|
struct netlink_ctx *ctx);
|
|
extern void netlink_dump_rule(const struct nftnl_rule *nlr,
|
|
diff --git a/src/cache.c b/src/cache.c
|
|
index 2407fc2..77a67f7 100644
|
|
--- a/src/cache.c
|
|
+++ b/src/cache.c
|
|
@@ -321,27 +321,49 @@ static unsigned int evaluate_cache_list(struct nft_ctx *nft, struct cmd *cmd,
|
|
static unsigned int evaluate_cache_reset(struct cmd *cmd, unsigned int flags,
|
|
struct nft_cache_filter *filter)
|
|
{
|
|
+ assert(filter);
|
|
+
|
|
switch (cmd->obj) {
|
|
+ case CMD_OBJ_TABLE:
|
|
+ case CMD_OBJ_CHAIN:
|
|
case CMD_OBJ_RULES:
|
|
case CMD_OBJ_RULE:
|
|
- if (filter) {
|
|
- if (cmd->handle.table.name) {
|
|
- filter->list.family = cmd->handle.family;
|
|
- filter->list.table = cmd->handle.table.name;
|
|
- }
|
|
- if (cmd->handle.chain.name)
|
|
- filter->list.chain = cmd->handle.chain.name;
|
|
+ if (cmd->handle.table.name) {
|
|
+ filter->list.family = cmd->handle.family;
|
|
+ filter->list.table = cmd->handle.table.name;
|
|
}
|
|
- flags |= NFT_CACHE_SET | NFT_CACHE_FLOWTABLE |
|
|
- NFT_CACHE_OBJECT | NFT_CACHE_CHAIN;
|
|
+ if (cmd->handle.chain.name)
|
|
+ filter->list.chain = cmd->handle.chain.name;
|
|
+ if (cmd->handle.family)
|
|
+ filter->list.family = cmd->handle.family;
|
|
+ if (cmd->handle.handle.id)
|
|
+ filter->list.rule_handle = cmd->handle.handle.id;
|
|
+
|
|
+ filter->reset.rule = true;
|
|
+ flags |= NFT_CACHE_FULL;
|
|
+ break;
|
|
+ case CMD_OBJ_COUNTER:
|
|
+ case CMD_OBJ_COUNTERS:
|
|
+ obj_filter_setup(cmd, &flags, filter, NFT_OBJECT_COUNTER);
|
|
+ filter->reset.obj = true;
|
|
+ break;
|
|
+ case CMD_OBJ_QUOTA:
|
|
+ case CMD_OBJ_QUOTAS:
|
|
+ obj_filter_setup(cmd, &flags, filter, NFT_OBJECT_QUOTA);
|
|
+ filter->reset.obj = true;
|
|
break;
|
|
- case CMD_OBJ_ELEMENTS:
|
|
case CMD_OBJ_SET:
|
|
case CMD_OBJ_MAP:
|
|
- flags |= NFT_CACHE_SET;
|
|
+ if (cmd->handle.table.name && cmd->handle.set.name) {
|
|
+ filter->list.family = cmd->handle.family;
|
|
+ filter->list.table = cmd->handle.table.name;
|
|
+ filter->list.set = cmd->handle.set.name;
|
|
+ }
|
|
+ flags |= NFT_CACHE_SETELEM;
|
|
+ filter->reset.elem = true;
|
|
break;
|
|
default:
|
|
- flags |= NFT_CACHE_TABLE;
|
|
+ flags |= NFT_CACHE_FULL;
|
|
break;
|
|
}
|
|
flags |= NFT_CACHE_REFRESH;
|
|
@@ -457,6 +479,7 @@ err_name_too_long:
|
|
static void reset_filter(struct nft_cache_filter *filter)
|
|
{
|
|
memset(&filter->list, 0, sizeof(filter->list));
|
|
+ memset(&filter->reset, 0, sizeof(filter->reset));
|
|
}
|
|
|
|
int nft_cache_evaluate(struct nft_ctx *nft, struct list_head *cmds,
|
|
@@ -700,23 +723,32 @@ static int list_rule_cb(struct nftnl_rule *nlr, void *data)
|
|
return 0;
|
|
}
|
|
|
|
-int rule_cache_dump(struct netlink_ctx *ctx, const struct handle *h,
|
|
- const struct nft_cache_filter *filter,
|
|
- bool dump, bool reset)
|
|
+static int rule_cache_dump(struct netlink_ctx *ctx, const struct handle *h,
|
|
+ const struct nft_cache_filter *filter)
|
|
{
|
|
struct nftnl_rule_list *rule_cache;
|
|
const char *table = h->table.name;
|
|
const char *chain = NULL;
|
|
uint64_t rule_handle = 0;
|
|
+ int family = h->family;
|
|
+ bool dump = true;
|
|
|
|
if (filter) {
|
|
- table = filter->list.table;
|
|
- chain = filter->list.chain;
|
|
- rule_handle = filter->list.rule_handle;
|
|
+ if (filter->list.table)
|
|
+ table = filter->list.table;
|
|
+ if (filter->list.chain)
|
|
+ chain = filter->list.chain;
|
|
+ if (filter->list.rule_handle) {
|
|
+ rule_handle = filter->list.rule_handle;
|
|
+ dump = false;
|
|
+ }
|
|
+ if (filter->list.family)
|
|
+ family = filter->list.family;
|
|
}
|
|
|
|
- rule_cache = mnl_nft_rule_dump(ctx, h->family,
|
|
- table, chain, rule_handle, dump, reset);
|
|
+ rule_cache = mnl_nft_rule_dump(ctx, family,
|
|
+ table, chain, rule_handle, dump,
|
|
+ filter->reset.rule);
|
|
if (rule_cache == NULL) {
|
|
if (errno == EINTR)
|
|
return -1;
|
|
@@ -900,7 +932,8 @@ static struct nftnl_obj_list *obj_cache_dump(struct netlink_ctx *ctx,
|
|
if (filter->list.obj_type)
|
|
type = filter->list.obj_type;
|
|
}
|
|
- obj_list = mnl_nft_obj_dump(ctx, family, table, obj, type, dump, false);
|
|
+ obj_list = mnl_nft_obj_dump(ctx, family, table, obj, type, dump,
|
|
+ filter->reset.obj);
|
|
if (!obj_list) {
|
|
if (errno == EINTR)
|
|
return NULL;
|
|
@@ -1074,7 +1107,7 @@ static int rule_init_cache(struct netlink_ctx *ctx, struct table *table,
|
|
struct chain *chain;
|
|
int ret;
|
|
|
|
- ret = rule_cache_dump(ctx, &table->handle, filter, true, false);
|
|
+ ret = rule_cache_dump(ctx, &table->handle, filter);
|
|
|
|
list_for_each_entry_safe(rule, nrule, &ctx->list, list) {
|
|
chain = chain_cache_find(table, rule->handle.chain.name);
|
|
@@ -1170,7 +1203,7 @@ static int cache_init_objects(struct netlink_ctx *ctx, unsigned int flags,
|
|
continue;
|
|
|
|
ret = netlink_list_setelems(ctx, &set->handle,
|
|
- set, false);
|
|
+ set, filter->reset.elem);
|
|
if (ret < 0)
|
|
goto cache_fails;
|
|
}
|
|
@@ -1183,7 +1216,7 @@ static int cache_init_objects(struct netlink_ctx *ctx, unsigned int flags,
|
|
continue;
|
|
|
|
ret = netlink_list_setelems(ctx, &set->handle,
|
|
- set, false);
|
|
+ set, filter->reset.elem);
|
|
if (ret < 0)
|
|
goto cache_fails;
|
|
}
|
|
diff --git a/src/evaluate.c b/src/evaluate.c
|
|
index af811a7..32d4c75 100644
|
|
--- a/src/evaluate.c
|
|
+++ b/src/evaluate.c
|
|
@@ -5669,6 +5669,8 @@ static int cmd_evaluate_reset(struct eval_ctx *ctx, struct cmd *cmd)
|
|
return 0;
|
|
case CMD_OBJ_ELEMENTS:
|
|
return setelem_evaluate(ctx, cmd);
|
|
+ case CMD_OBJ_TABLE:
|
|
+ case CMD_OBJ_CHAIN:
|
|
case CMD_OBJ_SET:
|
|
case CMD_OBJ_MAP:
|
|
return cmd_evaluate_list(ctx, cmd);
|
|
diff --git a/src/mnl.c b/src/mnl.c
|
|
index 9e4bfcd..9bddf10 100644
|
|
--- a/src/mnl.c
|
|
+++ b/src/mnl.c
|
|
@@ -1161,8 +1161,11 @@ struct nftnl_table_list *mnl_nft_table_dump(struct netlink_ctx *ctx,
|
|
if (!nlt)
|
|
memory_allocation_error();
|
|
|
|
- nftnl_table_set_u32(nlt, NFTNL_TABLE_FAMILY, family);
|
|
- nftnl_table_set_str(nlt, NFTNL_TABLE_NAME, table);
|
|
+ if (family != NFPROTO_UNSPEC)
|
|
+ nftnl_table_set_u32(nlt, NFTNL_TABLE_FAMILY, family);
|
|
+ if (table)
|
|
+ nftnl_table_set_str(nlt, NFTNL_TABLE_NAME, table);
|
|
+
|
|
flags = NLM_F_ACK;
|
|
}
|
|
|
|
diff --git a/src/netlink.c b/src/netlink.c
|
|
index 72f4ba4..0caeeff 100644
|
|
--- a/src/netlink.c
|
|
+++ b/src/netlink.c
|
|
@@ -1755,84 +1755,6 @@ void netlink_dump_flowtable(struct nftnl_flowtable *flo,
|
|
fprintf(fp, "\n");
|
|
}
|
|
|
|
-static int list_obj_cb(struct nftnl_obj *nls, void *arg)
|
|
-{
|
|
- struct netlink_ctx *ctx = arg;
|
|
- struct obj *obj;
|
|
-
|
|
- obj = netlink_delinearize_obj(ctx, nls);
|
|
- if (obj == NULL)
|
|
- return -1;
|
|
- list_add_tail(&obj->list, &ctx->list);
|
|
- return 0;
|
|
-}
|
|
-
|
|
-int netlink_reset_objs(struct netlink_ctx *ctx, const struct cmd *cmd,
|
|
- uint32_t type, bool dump)
|
|
-{
|
|
- const struct handle *h = &cmd->handle;
|
|
- struct nftnl_obj_list *obj_cache;
|
|
- int err;
|
|
-
|
|
- obj_cache = mnl_nft_obj_dump(ctx, h->family,
|
|
- h->table.name, h->obj.name, type, dump, true);
|
|
- if (obj_cache == NULL)
|
|
- return -1;
|
|
-
|
|
- err = nftnl_obj_list_foreach(obj_cache, list_obj_cb, ctx);
|
|
- nftnl_obj_list_free(obj_cache);
|
|
- return err;
|
|
-}
|
|
-
|
|
-int netlink_reset_rules(struct netlink_ctx *ctx, const struct cmd *cmd,
|
|
- bool dump)
|
|
-{
|
|
- const struct handle *h = &cmd->handle;
|
|
- struct nft_cache_filter f = {
|
|
- .list.table = h->table.name,
|
|
- .list.chain = h->chain.name,
|
|
- .list.rule_handle = h->handle.id,
|
|
- };
|
|
- struct rule *rule, *next, *crule, *cnext;
|
|
- struct table *table;
|
|
- struct chain *chain;
|
|
- int ret;
|
|
-
|
|
- ret = rule_cache_dump(ctx, h, &f, dump, true);
|
|
-
|
|
- list_for_each_entry_safe(rule, next, &ctx->list, list) {
|
|
- table = table_cache_find(&ctx->nft->cache.table_cache,
|
|
- rule->handle.table.name,
|
|
- rule->handle.family);
|
|
- if (!table)
|
|
- continue;
|
|
-
|
|
- chain = chain_cache_find(table, rule->handle.chain.name);
|
|
- if (!chain)
|
|
- continue;
|
|
-
|
|
- list_del(&rule->list);
|
|
- list_for_each_entry_safe(crule, cnext, &chain->rules, list) {
|
|
- if (crule->handle.handle.id != rule->handle.handle.id)
|
|
- continue;
|
|
-
|
|
- list_replace(&crule->list, &rule->list);
|
|
- rule_free(crule);
|
|
- rule = NULL;
|
|
- break;
|
|
- }
|
|
- if (rule) {
|
|
- list_add_tail(&rule->list, &chain->rules);
|
|
- }
|
|
- }
|
|
- list_for_each_entry_safe(rule, next, &ctx->list, list) {
|
|
- list_del(&rule->list);
|
|
- rule_free(rule);
|
|
- }
|
|
-
|
|
- return ret;
|
|
-}
|
|
-
|
|
struct flowtable *
|
|
netlink_delinearize_flowtable(struct netlink_ctx *ctx,
|
|
struct nftnl_flowtable *nlo)
|
|
diff --git a/src/parser_bison.y b/src/parser_bison.y
|
|
index c18e739..25a285c 100644
|
|
--- a/src/parser_bison.y
|
|
+++ b/src/parser_bison.y
|
|
@@ -1753,21 +1753,21 @@ reset_cmd : COUNTERS ruleset_spec
|
|
}
|
|
| RULES table_spec
|
|
{
|
|
- $$ = cmd_alloc(CMD_RESET, CMD_OBJ_RULES, &$2, &@$, NULL);
|
|
+ $$ = cmd_alloc(CMD_RESET, CMD_OBJ_TABLE, &$2, &@$, NULL);
|
|
}
|
|
| RULES TABLE table_spec
|
|
{
|
|
/* alias of previous rule. */
|
|
- $$ = cmd_alloc(CMD_RESET, CMD_OBJ_RULES, &$3, &@$, NULL);
|
|
+ $$ = cmd_alloc(CMD_RESET, CMD_OBJ_TABLE, &$3, &@$, NULL);
|
|
}
|
|
| RULES chain_spec
|
|
{
|
|
- $$ = cmd_alloc(CMD_RESET, CMD_OBJ_RULES, &$2, &@$, NULL);
|
|
+ $$ = cmd_alloc(CMD_RESET, CMD_OBJ_CHAIN, &$2, &@$, NULL);
|
|
}
|
|
| RULES CHAIN chain_spec
|
|
{
|
|
/* alias of previous rule. */
|
|
- $$ = cmd_alloc(CMD_RESET, CMD_OBJ_RULES, &$3, &@$, NULL);
|
|
+ $$ = cmd_alloc(CMD_RESET, CMD_OBJ_CHAIN, &$3, &@$, NULL);
|
|
}
|
|
| RULE ruleid_spec
|
|
{
|
|
diff --git a/src/rule.c b/src/rule.c
|
|
index 89101f9..683e69b 100644
|
|
--- a/src/rule.c
|
|
+++ b/src/rule.c
|
|
@@ -2463,58 +2463,12 @@ static int do_command_get(struct netlink_ctx *ctx, struct cmd *cmd)
|
|
|
|
static int do_command_reset(struct netlink_ctx *ctx, struct cmd *cmd)
|
|
{
|
|
- struct obj *obj, *next;
|
|
- struct table *table;
|
|
- bool dump = false;
|
|
- uint32_t type;
|
|
- int ret;
|
|
-
|
|
switch (cmd->obj) {
|
|
- case CMD_OBJ_COUNTERS:
|
|
- dump = true;
|
|
- /* fall through */
|
|
- case CMD_OBJ_COUNTER:
|
|
- type = NFT_OBJECT_COUNTER;
|
|
- break;
|
|
- case CMD_OBJ_QUOTAS:
|
|
- dump = true;
|
|
- /* fall through */
|
|
- case CMD_OBJ_QUOTA:
|
|
- type = NFT_OBJECT_QUOTA;
|
|
- break;
|
|
- case CMD_OBJ_RULES:
|
|
- ret = netlink_reset_rules(ctx, cmd, true);
|
|
- if (ret < 0)
|
|
- return ret;
|
|
-
|
|
- return do_command_list(ctx, cmd);
|
|
- case CMD_OBJ_RULE:
|
|
- return netlink_reset_rules(ctx, cmd, false);
|
|
case CMD_OBJ_ELEMENTS:
|
|
return do_get_setelems(ctx, cmd, true);
|
|
- case CMD_OBJ_SET:
|
|
- case CMD_OBJ_MAP:
|
|
- ret = netlink_list_setelems(ctx, &cmd->handle, cmd->set, true);
|
|
- if (ret < 0)
|
|
- return ret;
|
|
-
|
|
- return do_command_list(ctx, cmd);
|
|
default:
|
|
- BUG("invalid command object type %u\n", cmd->obj);
|
|
- }
|
|
-
|
|
- ret = netlink_reset_objs(ctx, cmd, type, dump);
|
|
- list_for_each_entry_safe(obj, next, &ctx->list, list) {
|
|
- table = table_cache_find(&ctx->nft->cache.table_cache,
|
|
- obj->handle.table.name,
|
|
- obj->handle.family);
|
|
- if (!obj_cache_find(table, obj->handle.obj.name, obj->type)) {
|
|
- list_del(&obj->list);
|
|
- obj_cache_add(obj, table);
|
|
- }
|
|
+ break;
|
|
}
|
|
- if (ret < 0)
|
|
- return ret;
|
|
|
|
return do_command_list(ctx, cmd);
|
|
}
|
|
diff --git a/tests/shell/testcases/rule_management/0011reset_0 b/tests/shell/testcases/rule_management/0011reset_0
|
|
index 33eadd9..3fede56 100755
|
|
--- a/tests/shell/testcases/rule_management/0011reset_0
|
|
+++ b/tests/shell/testcases/rule_management/0011reset_0
|
|
@@ -74,13 +74,6 @@ $DIFF -u <(echo "$EXPECT") <($NFT list ruleset)
|
|
|
|
echo "resetting specific chain"
|
|
EXPECT='table ip t {
|
|
- set s {
|
|
- type ipv4_addr
|
|
- size 65535
|
|
- flags dynamic
|
|
- counter
|
|
- }
|
|
-
|
|
chain c2 {
|
|
counter packets 3 bytes 13 accept
|
|
counter packets 4 bytes 14 drop
|
|
@@ -95,6 +88,7 @@ EXPECT='table ip t {
|
|
size 65535
|
|
flags dynamic
|
|
counter
|
|
+ elements = { 1.1.1.1 counter packets 1 bytes 11 }
|
|
}
|
|
|
|
chain c {
|
|
@@ -116,6 +110,7 @@ EXPECT='table ip t {
|
|
size 65535
|
|
flags dynamic
|
|
counter
|
|
+ elements = { 1.1.1.1 counter packets 1 bytes 11 }
|
|
}
|
|
|
|
chain c {
|
|
@@ -143,6 +138,7 @@ EXPECT='table ip t {
|
|
size 65535
|
|
flags dynamic
|
|
counter
|
|
+ elements = { 1.1.1.1 counter packets 1 bytes 11 }
|
|
}
|
|
|
|
chain c {
|