diff options
| author | Pablo Neira Ayuso <pablo@netfilter.org> | 2020-04-07 14:10:38 +0200 | 
|---|---|---|
| committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2020-04-07 18:23:04 +0200 | 
| commit | ef516e8625ddea90b3a0313f3a0b0baa83db7ac2 (patch) | |
| tree | 8467bbd448f09238f57c4f080f8eec074de7af5b /include/uapi | |
| parent | d9583cdf2f38d0f526d9a8c8564dd2e35e649bc7 (diff) | |
| download | linux-ef516e8625ddea90b3a0313f3a0b0baa83db7ac2.tar.bz2 | |
netfilter: nf_tables: reintroduce the NFT_SET_CONCAT flag
Stefano originally proposed to introduce this flag, users hit EOPNOTSUPP
in new binaries with old kernels when defining a set with ranges in
a concatenation.
Fixes: f3a2181e16f1 ("netfilter: nf_tables: Support for sets with multiple ranged fields")
Reviewed-by: Stefano Brivio <sbrivio@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/uapi')
| -rw-r--r-- | include/uapi/linux/netfilter/nf_tables.h | 2 | 
1 files changed, 2 insertions, 0 deletions
| diff --git a/include/uapi/linux/netfilter/nf_tables.h b/include/uapi/linux/netfilter/nf_tables.h index 30f2a87270dc..4565456c0ef4 100644 --- a/include/uapi/linux/netfilter/nf_tables.h +++ b/include/uapi/linux/netfilter/nf_tables.h @@ -276,6 +276,7 @@ enum nft_rule_compat_attributes {   * @NFT_SET_TIMEOUT: set uses timeouts   * @NFT_SET_EVAL: set can be updated from the evaluation path   * @NFT_SET_OBJECT: set contains stateful objects + * @NFT_SET_CONCAT: set contains a concatenation   */  enum nft_set_flags {  	NFT_SET_ANONYMOUS		= 0x1, @@ -285,6 +286,7 @@ enum nft_set_flags {  	NFT_SET_TIMEOUT			= 0x10,  	NFT_SET_EVAL			= 0x20,  	NFT_SET_OBJECT			= 0x40, +	NFT_SET_CONCAT			= 0x80,  };  /** |