All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dennis Jacobfeuerborn <dennisml@conversis.de>
To: Pascal Hambourg <pascal@plouf.fr.eu.org>, netfilter@vger.kernel.org
Subject: Re: bug in iptables-restore and "recent" module
Date: Tue, 17 Feb 2015 12:12:30 +0100	[thread overview]
Message-ID: <54E3221E.5050909@conversis.de> (raw)
In-Reply-To: <54E30166.1090406@plouf.fr.eu.org>

On 17.02.2015 09:52, Pascal Hambourg wrote:
> richard lucassen a écrit :
>> On Mon, 16 Feb 2015 00:08:41 +0100
>> Pascal Hambourg <pascal@plouf.fr.eu.org> wrote:
>>
>>>> On line 180 there is the "COMMIT" of the filter table.
>>> That sounds like expected behaviour. Where's the bug ?
>>
>> I'd say in iptables-restore. Apparently the -t (test) does not notice
>> that there is a problem while the real iptables-restore does.
> 
> Sorry, my question was not clear enough. Let me rephrase.
> 
> As -t does not commit the tables to the kernel, I do not expect it to
> detect errors related to the kernel configuration. So I do not see any
> bug in your description, it sounds like expected behaviour to me. Where
> do you see a bug in that behaviour ?

This should probably be mentioned in the man page. Most people would
think that if the ruleset passes a test with -t this means the ruleset
can be activated. Which part specifically of the mentioned rule is it
that cannot be tested without being committed the rule in the kernel?

Regards,
  Dennis

  reply	other threads:[~2015-02-17 11:12 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-02-15 12:31 bug in iptables-restore and "recent" module richard lucassen
2015-02-15 23:08 ` Pascal Hambourg
2015-02-16 22:53   ` richard lucassen
2015-02-17  8:52     ` Pascal Hambourg
2015-02-17 11:12       ` Dennis Jacobfeuerborn [this message]
2015-03-02  7:52         ` richard lucassen
2015-02-20 21:05       ` richard lucassen
2015-02-20 21:22         ` Neal Murphy

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=54E3221E.5050909@conversis.de \
    --to=dennisml@conversis.de \
    --cc=netfilter@vger.kernel.org \
    --cc=pascal@plouf.fr.eu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.