All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tomasz Bursztyka <tomasz.bursztyka@linux.intel.com>
To: Giuseppe Longo <giuseppelng@gmail.com>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [xtables-arptables PATCH 3/4] nft: nft_xtables_config_load() called only in nft_init()
Date: Mon, 22 Jul 2013 18:35:49 +0300	[thread overview]
Message-ID: <51ED5155.7020306@linux.intel.com> (raw)
In-Reply-To: <20130716223053.13253.90159.stgit@nftables>

Hi Giuseppe,

You haven't tested your patch, have you?

You need to change nft_init() so it takes the family to give to the 
handle as a parameter. Only then nft_xtables_config_load will work.
That said, you will have to move nft_init() into xtables.c and remove it 
from xtables-standalone.c
and fix xtables-save.c, xtables-restore.c etc... (move the nft_init() 
part after the command parsing in those, so you can put h.family as 
family param, for instance)
I quickly tried and it works well that way.

About xtables-config.c, you have to add the config filename as a paremet 
to nft_init() as well. it will be required anyway for arptables too!

Cheers,

Tomasz

> Signed-off-by: Giuseppe Longo <giuseppelng@gmail.com>
> ---
>   iptables/nft.c |   28 ++++++++--------------------
>   1 file changed, 8 insertions(+), 20 deletions(-)
>
> diff --git a/iptables/nft.c b/iptables/nft.c
> index 9a8986a..198c41e 100644
> --- a/iptables/nft.c
> +++ b/iptables/nft.c
> @@ -388,6 +388,14 @@ int nft_init(struct nft_handle *h)
>   	h->portid = mnl_socket_get_portid(h->nl);
>   	h->tables = tables;
>   
> +	/* If built-in chains don't exist for this table, create them */
> +	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0) {
> +		int i;
> +
> +		for (i=0; i<TABLES_MAX; i++)
> +			if (h->tables[i].name != NULL)
> +				nft_chain_builtin_init(h, h->tables[i].name, NULL, NF_ACCEPT);
> +	}
>   	return 0;
>   }
>   
> @@ -742,10 +750,6 @@ nft_rule_append(struct nft_handle *h, const char *chain, const char *table,
>   	uint16_t flags = NLM_F_ACK|NLM_F_CREATE;
>   	int ret = 1;
>   
> -	/* If built-in chains don't exist for this table, create them */
> -	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0)
> -		nft_chain_builtin_init(h, table, chain, NF_ACCEPT);
> -
>   	nft_fn = nft_rule_append;
>   
>   	r = nft_rule_new(h, chain, table, cs);
> @@ -1316,10 +1320,6 @@ int nft_chain_user_add(struct nft_handle *h, const char *chain, const char *tabl
>   	struct nft_chain *c;
>   	int ret;
>   
> -	/* If built-in chains don't exist for this table, create them */
> -	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0)
> -		nft_chain_builtin_init(h, table, NULL, NF_ACCEPT);
> -
>   	c = nft_chain_alloc();
>   	if (c == NULL)
>   		return 0;
> @@ -1472,10 +1472,6 @@ int nft_chain_user_rename(struct nft_handle *h,const char *chain,
>   	uint64_t handle;
>   	int ret;
>   
> -	/* If built-in chains don't exist for this table, create them */
> -	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0)
> -		nft_chain_builtin_init(h, table, NULL, NF_ACCEPT);
> -
>   	/* Find the old chain to be renamed */
>   	c = nft_chain_find(h, table, chain);
>   	if (c == NULL) {
> @@ -2170,10 +2166,6 @@ int nft_rule_insert(struct nft_handle *h, const char *chain,
>   	struct nft_rule *r;
>   	uint64_t handle;
>   
> -	/* If built-in chains don't exist for this table, create them */
> -	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0)
> -		nft_chain_builtin_init(h, table, chain, NF_ACCEPT);
> -
>   	nft_fn = nft_rule_insert;
>   
>   	list = nft_rule_list_create(h);
> @@ -2521,10 +2513,6 @@ int nft_rule_list(struct nft_handle *h, const char *chain, const char *table,
>   	struct nft_chain *c;
>   	bool found = false;
>   
> -	/* If built-in chains don't exist for this table, create them */
> -	if (nft_xtables_config_load(h, XTABLES_CONFIG_DEFAULT, 0) < 0)
> -		nft_chain_builtin_init(h, table, NULL, NF_ACCEPT);
> -
>   	list = nft_chain_dump(h);
>   
>   	iter = nft_chain_list_iter_create(list);
>
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>


  reply	other threads:[~2013-07-22 15:36 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-07-16 22:30 [xtables-arptables PATCH 0/4] nft changes for xtables-arptables Giuseppe Longo
2013-07-16 22:30 ` [xtables-arptables PATCH 1/4] nft: add builtin_table pointer Giuseppe Longo
2013-07-16 22:30 ` [xtables-arptables PATCH 2/4] nft: search builtin tables via nft_handle tables pointer Giuseppe Longo
2013-07-16 22:30 ` [xtables-arptables PATCH 3/4] nft: nft_xtables_config_load() called only in nft_init() Giuseppe Longo
2013-07-22 15:35   ` Tomasz Bursztyka [this message]
2013-07-22 15:41   ` Tomasz Bursztyka
2013-07-16 22:31 ` [xtables-arptables PATCH 4/4] nft: make functions public Giuseppe Longo
2013-07-22 15:43 ` [xtables-arptables PATCH 0/4] nft changes for xtables-arptables Tomasz Bursztyka

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=51ED5155.7020306@linux.intel.com \
    --to=tomasz.bursztyka@linux.intel.com \
    --cc=giuseppelng@gmail.com \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.