netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [nft crap] ct original ip saddr ... handling
@ 2017-06-28 10:06 Florian Westphal
  2017-06-28 10:06 ` [PATCH 01/17] rename struct ct to ct_helper Florian Westphal
                   ` (11 more replies)
  0 siblings, 12 replies; 22+ messages in thread
From: Florian Westphal @ 2017-06-28 10:06 UTC (permalink / raw)
  To: netfilter-devel

I am running out of time so I have to send this unfinished/non-working
state.

It breaks because ct is riddled with conflicts,
in nft we've handled original/reply as STRING to avoid conflicts
with 'arp reply', so we cannot add

ct original ip saddr

because it is
ct STRING	IP	SADDR

and that conflicts with basic use where 'ip saddr' could be payload
expression, and STRING is one of the normal ct tokens and not a direction.

I am trying to fix this here by moving all ct keywords back to tokens.
There are no shift/reduce errors, things compile fine, and all
test cases work.  Its just that we break 'ct event set label':

Works:
ct event set new or reply
ct event set new,reply
ct event set new,label
fails:
ct event set label ('expects COMMA')

Other than that it should work, this also adds dependency removal
for meta and ct when de-linearizing rulesets and gets rid of
the uneeded meta dependency when using rt nexthop in inet table.


^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2017-07-18 16:54 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-06-28 10:06 [nft crap] ct original ip saddr ... handling Florian Westphal
2017-06-28 10:06 ` [PATCH 01/17] rename struct ct to ct_helper Florian Westphal
2017-07-18 16:54   ` Pablo Neira Ayuso
2017-06-28 10:06 ` [PATCH 02/17] src: prepare for future ct timeout policy support Florian Westphal
2017-06-28 10:06 ` [PATCH 03/17] parser: use scanner tokens again for ct key handling Florian Westphal
2017-06-28 10:06 ` [PATCH 04/17] parser: compact list of rhs keyword expressions Florian Westphal
2017-06-28 10:06 ` [PATCH 05/17] bison: permit 'label' on rhs side of expression Florian Westphal
2017-06-28 10:06 ` [PATCH 06/17] bison: permit keywords in list_stmt_expressions Florian Westphal
2017-06-28 10:06 ` [PATCH 07/17] tests: ct: remove unsupported syntax Florian Westphal
2017-06-28 10:06 ` [PATCH 08/17] src: add alternate syntax for ct saddr Florian Westphal
2017-06-28 10:06 ` [PATCH 09/17] src: ct: store proto base of ct key, if any Florian Westphal
2017-06-28 10:06 ` [PATCH 10/17] src: ct: add eval part to inject dependencies for ct saddr/daddr Florian Westphal
2017-06-28 10:14 ` [PATCH 11/17] src: unifiy meta and ct postprocessing Florian Westphal
2017-06-28 10:14   ` [PATCH 12/17] tests: update inet/bridge icmp test case Florian Westphal
2017-06-28 10:14   ` [PATCH 13/17] src: ct: print nfproto name for some header fields Florian Westphal
2017-06-28 10:14   ` [PATCH 14/17] tests: ct: adjust test case commands Florian Westphal
2017-06-28 10:14   ` [PATCH 15/17] src: rt: add keyword distinction for nexthop vs nexthop6 Florian Westphal
2017-06-28 10:14   ` [PATCH 16/17] tests: rt: fix test cases Florian Westphal
2017-06-28 10:14   ` [PATCH 17/17] doc: update man page Florian Westphal
2017-06-28 16:35 ` [nft crap] ct original ip saddr ... handling Pablo Neira Ayuso
2017-06-28 22:31   ` Florian Westphal
2017-06-29  0:39     ` Florian Westphal

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).