From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Phil Sutter <phil@nwl.cc>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [iptables PATCH 1/4] nft: Set NFTNL_CHAIN_FAMILY in new chains
Date: Mon, 7 Feb 2022 18:59:54 +0100 [thread overview]
Message-ID: <YgFeGpsoHO4wjGU0@salvia> (raw)
In-Reply-To: <20220204170001.27198-1-phil@nwl.cc>
Series LGTM, thanks
On Fri, Feb 04, 2022 at 05:59:58PM +0100, Phil Sutter wrote:
> Kernel doesn't need it, but debug output improves significantly. Before
> this patch:
>
> | # iptables-nft -vv -A INPUT
> | [...]
> | unknown filter INPUT use 0 type filter hook unknown prio 0 policy accept packets 0 bytes 0
> | [...]
>
> and after:
>
> | # iptables-nft -vv -A INPUT
> | [...]
> | ip filter INPUT use 0 type filter hook input prio 0 policy accept packets 0 bytes 0
> | [...]
>
> While being at it, make nft_chain_builtin_alloc() take only the builtin
> table's name as parameter - it's the only field it accesses.
>
> Signed-off-by: Phil Sutter <phil@nwl.cc>
> ---
> iptables/nft.c | 12 ++++++++----
> 1 file changed, 8 insertions(+), 4 deletions(-)
>
> diff --git a/iptables/nft.c b/iptables/nft.c
> index 7cc6ca5258150..301d6c342f982 100644
> --- a/iptables/nft.c
> +++ b/iptables/nft.c
> @@ -665,7 +665,7 @@ static int nft_table_builtin_add(struct nft_handle *h,
> }
>
> static struct nftnl_chain *
> -nft_chain_builtin_alloc(const struct builtin_table *table,
> +nft_chain_builtin_alloc(int family, const char *tname,
> const struct builtin_chain *chain, int policy)
> {
> struct nftnl_chain *c;
> @@ -674,7 +674,8 @@ nft_chain_builtin_alloc(const struct builtin_table *table,
> if (c == NULL)
> return NULL;
>
> - nftnl_chain_set_str(c, NFTNL_CHAIN_TABLE, table->name);
> + nftnl_chain_set_u32(c, NFTNL_CHAIN_FAMILY, family);
> + nftnl_chain_set_str(c, NFTNL_CHAIN_TABLE, tname);
> nftnl_chain_set_str(c, NFTNL_CHAIN_NAME, chain->name);
> nftnl_chain_set_u32(c, NFTNL_CHAIN_HOOKNUM, chain->hook);
> nftnl_chain_set_u32(c, NFTNL_CHAIN_PRIO, chain->prio);
> @@ -693,7 +694,7 @@ static void nft_chain_builtin_add(struct nft_handle *h,
> {
> struct nftnl_chain *c;
>
> - c = nft_chain_builtin_alloc(table, chain, NF_ACCEPT);
> + c = nft_chain_builtin_alloc(h->family, table->name, chain, NF_ACCEPT);
> if (c == NULL)
> return;
>
> @@ -959,7 +960,7 @@ static struct nftnl_chain *nft_chain_new(struct nft_handle *h,
> _c = nft_chain_builtin_find(_t, chain);
> if (_c != NULL) {
> /* This is a built-in chain */
> - c = nft_chain_builtin_alloc(_t, _c, policy);
> + c = nft_chain_builtin_alloc(h->family, _t->name, _c, policy);
> if (c == NULL)
> return NULL;
> } else {
> @@ -1999,6 +2000,7 @@ int nft_chain_user_add(struct nft_handle *h, const char *chain, const char *tabl
> if (c == NULL)
> return 0;
>
> + nftnl_chain_set_u32(c, NFTNL_CHAIN_FAMILY, h->family);
> nftnl_chain_set_str(c, NFTNL_CHAIN_TABLE, table);
> nftnl_chain_set_str(c, NFTNL_CHAIN_NAME, chain);
> if (h->family == NFPROTO_BRIDGE)
> @@ -2029,6 +2031,7 @@ int nft_chain_restore(struct nft_handle *h, const char *chain, const char *table
> if (!c)
> return 0;
>
> + nftnl_chain_set_u32(c, NFTNL_CHAIN_FAMILY, h->family);
> nftnl_chain_set_str(c, NFTNL_CHAIN_TABLE, table);
> nftnl_chain_set_str(c, NFTNL_CHAIN_NAME, chain);
> created = true;
> @@ -2190,6 +2193,7 @@ int nft_chain_user_rename(struct nft_handle *h,const char *chain,
> if (c == NULL)
> return 0;
>
> + nftnl_chain_set_u32(c, NFTNL_CHAIN_FAMILY, h->family);
> nftnl_chain_set_str(c, NFTNL_CHAIN_TABLE, table);
> nftnl_chain_set_str(c, NFTNL_CHAIN_NAME, newname);
> nftnl_chain_set_u64(c, NFTNL_CHAIN_HANDLE, handle);
> --
> 2.34.1
>
prev parent reply other threads:[~2022-02-07 18:03 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-02-04 16:59 [iptables PATCH 1/4] nft: Set NFTNL_CHAIN_FAMILY in new chains Phil Sutter
2022-02-04 16:59 ` [iptables PATCH 2/4] ebtables: Support verbose mode Phil Sutter
2022-02-04 17:00 ` [iptables PATCH 3/4] nft: Add debug output to table creation Phil Sutter
2022-02-04 17:00 ` [iptables PATCH 4/4] nft: cache: Dump rules if debugging Phil Sutter
2022-02-07 17:59 ` Pablo Neira Ayuso [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YgFeGpsoHO4wjGU0@salvia \
--to=pablo@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=phil@nwl.cc \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.