All of lore.kernel.org
 help / color / mirror / Atom feed
* Matching metainformation cgroup fails on input, works on output.
@ 2021-12-08  9:07 Vladimir Nikishkin
  2021-12-08 14:07 ` Martin Gignac
  0 siblings, 1 reply; 4+ messages in thread
From: Vladimir Nikishkin @ 2021-12-08  9:07 UTC (permalink / raw)
  To: netfilter

Hello, everyone.

I have a weird problem!

This is my nft code:

```
nft add counter filter test-icmp-output
nft add counter filter test-icmp-input
nft add rule filter OUTPUT meta cgroup != 0x001000 ip daddr 8.8.8.8 ip protocol icmp counter name test-icmp-output
nft add rule filter INPUT  meta cgroup != 0x001000 ip saddr 8.8.8.8 ip protocol icmp counter name test-icmp-input
```

Pinging 8.8.8.8 works. The packets are visible on tcpdump too.
The cgroup id 0x001000 does not exist, so every packet should match.

Still, the output counter counts the expected number of packets, the
second stays 0.

What am I doing wrong?

-- 
Your sincerely,
Vladimir Nikishkin (MiEr, lockywolf)
(Laptop)

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-12-08 14:51 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-12-08  9:07 Matching metainformation cgroup fails on input, works on output Vladimir Nikishkin
2021-12-08 14:07 ` Martin Gignac
2021-12-08 14:17   ` Vladimir Nikishkin
2021-12-08 14:51     ` Martin Gignac

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.