All of lore.kernel.org
 help / color / mirror / Atom feed
* [Bug] Reverse translation skips "leading" meta protocol match
@ 2021-08-26  4:10 Tom Yan
  2021-08-26  4:13 ` Tom Yan
  2021-08-26 10:51 ` Pablo Neira Ayuso
  0 siblings, 2 replies; 3+ messages in thread
From: Tom Yan @ 2021-08-26  4:10 UTC (permalink / raw)
  To: netfilter-devel

Hi,

Please see the following for details:

# nft --debug=netlink list table bridge meh
bridge meh hmm 2
  [ meta load l4proto => reg 1 ]
  [ cmp eq reg 1 0x00000011 ]
  [ payload load 2b @ transport header + 2 => reg 1 ]
  [ cmp eq reg 1 0x00004300 ]
  [ immediate reg 0 accept ]

bridge meh hmm 3 2
  [ meta load protocol => reg 1 ]
  [ cmp eq reg 1 0x00000008 ]
  [ meta load l4proto => reg 1 ]
  [ cmp eq reg 1 0x00000011 ]
  [ payload load 2b @ transport header + 2 => reg 1 ]
  [ cmp eq reg 1 0x00004300 ]
  [ immediate reg 0 accept ]

bridge meh hmm 4 3
  [ meta load l4proto => reg 1 ]
  [ cmp eq reg 1 0x00000011 ]
  [ payload load 2b @ transport header + 2 => reg 1 ]
  [ cmp eq reg 1 0x00004300 ]
  [ meta load protocol => reg 1 ]
  [ cmp eq reg 1 0x00000008 ]
  [ immediate reg 0 accept ]

table bridge meh {
    chain hmm {
        udp dport 67 accept
        udp dport 67 accept
        udp dport 67 meta protocol ip accept
    }
}

Regards,
Tom

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Bug] Reverse translation skips "leading" meta protocol match
  2021-08-26  4:10 [Bug] Reverse translation skips "leading" meta protocol match Tom Yan
@ 2021-08-26  4:13 ` Tom Yan
  2021-08-26 10:51 ` Pablo Neira Ayuso
  1 sibling, 0 replies; 3+ messages in thread
From: Tom Yan @ 2021-08-26  4:13 UTC (permalink / raw)
  To: netfilter-devel

Actually, rather than "leading", it's actually "non-trailing".

On Thu, 26 Aug 2021 at 12:10, Tom Yan <tom.ty89@gmail.com> wrote:
>
> Hi,
>
> Please see the following for details:
>
> # nft --debug=netlink list table bridge meh
> bridge meh hmm 2
>   [ meta load l4proto => reg 1 ]
>   [ cmp eq reg 1 0x00000011 ]
>   [ payload load 2b @ transport header + 2 => reg 1 ]
>   [ cmp eq reg 1 0x00004300 ]
>   [ immediate reg 0 accept ]
>
> bridge meh hmm 3 2
>   [ meta load protocol => reg 1 ]
>   [ cmp eq reg 1 0x00000008 ]
>   [ meta load l4proto => reg 1 ]
>   [ cmp eq reg 1 0x00000011 ]
>   [ payload load 2b @ transport header + 2 => reg 1 ]
>   [ cmp eq reg 1 0x00004300 ]
>   [ immediate reg 0 accept ]
>
> bridge meh hmm 4 3
>   [ meta load l4proto => reg 1 ]
>   [ cmp eq reg 1 0x00000011 ]
>   [ payload load 2b @ transport header + 2 => reg 1 ]
>   [ cmp eq reg 1 0x00004300 ]
>   [ meta load protocol => reg 1 ]
>   [ cmp eq reg 1 0x00000008 ]
>   [ immediate reg 0 accept ]
>
> table bridge meh {
>     chain hmm {
>         udp dport 67 accept
>         udp dport 67 accept
>         udp dport 67 meta protocol ip accept
>     }
> }
>
> Regards,
> Tom

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [Bug] Reverse translation skips "leading" meta protocol match
  2021-08-26  4:10 [Bug] Reverse translation skips "leading" meta protocol match Tom Yan
  2021-08-26  4:13 ` Tom Yan
@ 2021-08-26 10:51 ` Pablo Neira Ayuso
  1 sibling, 0 replies; 3+ messages in thread
From: Pablo Neira Ayuso @ 2021-08-26 10:51 UTC (permalink / raw)
  To: Tom Yan; +Cc: netfilter-devel

On Thu, Aug 26, 2021 at 12:10:05PM +0800, Tom Yan wrote:
[...]
> bridge meh hmm 3 2
>   [ meta load protocol => reg 1 ]
>   [ cmp eq reg 1 0x00000008 ]
>   [ meta load l4proto => reg 1 ]
>   [ cmp eq reg 1 0x00000011 ]
>   [ payload load 2b @ transport header + 2 => reg 1 ]
>   [ cmp eq reg 1 0x00004300 ]
>   [ immediate reg 0 accept ]

https://patchwork.ozlabs.org/project/netfilter-devel/patch/20210826104952.4812-1-pablo@netfilter.org/

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-08-26 10:51 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-08-26  4:10 [Bug] Reverse translation skips "leading" meta protocol match Tom Yan
2021-08-26  4:13 ` Tom Yan
2021-08-26 10:51 ` Pablo Neira Ayuso

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.