commit | 365b5a36f352e9884e85c47aa33026fd4df18633 | [log] [tgz] |
---|---|---|
author | Máté Eckl <ecklm94@gmail.com> | Thu Jul 12 17:18:46 2018 +0200 |
committer | Pablo Neira Ayuso <pablo@netfilter.org> | Wed Jul 18 11:26:51 2018 +0200 |
tree | 3fec6e319e62c7265b089e11b2b3df18ca49f564 | |
parent | 31a9c29210e2d8129d2e81acb89babb56916c6c9 [diff] |
netfilter: nft_socket: Break evaluation if no socket found Actual implementation stores 0 in the destination register if no socket is found by the lookup, but that is not intentional as it is not really a value of any socket metadata. This patch fixes this and breaks rule evaluation in this case. Fixes: 554ced0a6e29 ("netfilter: nf_tables: add support for native socket matching") Signed-off-by: Máté Eckl <ecklm94@gmail.com> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>