diff --git a/.gitignore b/.gitignore index d0729c1..3814395 100644 --- a/.gitignore +++ b/.gitignore @@ -12,3 +12,8 @@ /iptables-1.8.6.tar.bz2 /iptables-1.8.7.tar.bz2 /iptables-1.8.8.tar.bz2 +/iptables-1.8.9.tar.xz +/iptables-1.8.10.tar.xz +/iptables-1.8.10.tar.xz.sig +/iptables-1.8.11.tar.xz +/iptables-1.8.11.tar.xz.sig diff --git a/0001-xshared-Fix-build-for-Werror-format-security.patch b/0001-xshared-Fix-build-for-Werror-format-security.patch deleted file mode 100644 index 004c30d..0000000 --- a/0001-xshared-Fix-build-for-Werror-format-security.patch +++ /dev/null @@ -1,29 +0,0 @@ -From fe9bd3b29dd7661e6f74c24db8356014798d1d78 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 13 May 2022 16:51:58 +0200 -Subject: [PATCH] xshared: Fix build for -Werror=format-security - -Gcc complains about the omitted format string. - -Signed-off-by: Phil Sutter -(cherry picked from commit b72eb12ea5a61df0655ad99d5048994e916be83a) ---- - iptables/xshared.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/iptables/xshared.c b/iptables/xshared.c -index fae5ddd5df93e..a8512d3808154 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -1307,7 +1307,7 @@ static void check_empty_interface(struct xtables_args *args, const char *arg) - return; - - if (args->family != NFPROTO_ARP) -- xtables_error(PARAMETER_PROBLEM, msg); -+ xtables_error(PARAMETER_PROBLEM, "%s", msg); - - fprintf(stderr, "%s", msg); - } --- -2.38.0 - diff --git a/0002-Revert-fix-build-for-missing-ETH_ALEN-definition.patch b/0002-Revert-fix-build-for-missing-ETH_ALEN-definition.patch deleted file mode 100644 index ebc6bf6..0000000 --- a/0002-Revert-fix-build-for-missing-ETH_ALEN-definition.patch +++ /dev/null @@ -1,66 +0,0 @@ -From bafa9bcae3834c8cb723e07c9b1ea447c48514f5 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 18 May 2022 16:04:09 +0200 -Subject: [PATCH] Revert "fix build for missing ETH_ALEN definition" -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -This reverts commit c5d9a723b5159a28f547b577711787295a14fd84 as it broke -compiling against musl libc. Might be a bug in the latter, but for the -time being try to please both by avoiding the include and instead -defining ETH_ALEN if unset. - -While being at it, move netinet/ether.h include up. - -Fixes: 1bdb5535f561a ("libxtables: Extend MAC address printing/parsing support") -Signed-off-by: Phil Sutter -Reviewed-by: Maciej Żenczykowski -(cherry picked from commit 0e7cf0ad306cdf95dc3c28d15a254532206a888e) ---- - libxtables/xtables.c | 8 +++++--- - 1 file changed, 5 insertions(+), 3 deletions(-) - -diff --git a/libxtables/xtables.c b/libxtables/xtables.c -index 96fd783a066cf..0638f9271c601 100644 ---- a/libxtables/xtables.c -+++ b/libxtables/xtables.c -@@ -28,6 +28,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -45,7 +46,6 @@ - - #include - #include /* INT_MAX in ip_tables.h/ip6_tables.h */ --#include /* ETH_ALEN */ - #include - #include - #include -@@ -72,6 +72,10 @@ - #define PROC_SYS_MODPROBE "/proc/sys/kernel/modprobe" - #endif - -+#ifndef ETH_ALEN -+#define ETH_ALEN 6 -+#endif -+ - /* we need this for ip6?tables-restore. ip6?tables-restore.c sets line to the - * current line of the input file, in order to give a more precise error - * message. ip6?tables itself doesn't need this, so it is initialized to the -@@ -2245,8 +2249,6 @@ void xtables_print_num(uint64_t number, unsigned int format) - printf(FMT("%4lluT ","%lluT "), (unsigned long long)number); - } - --#include -- - static const unsigned char mac_type_unicast[ETH_ALEN] = {}; - static const unsigned char msk_type_unicast[ETH_ALEN] = {1}; - static const unsigned char mac_type_multicast[ETH_ALEN] = {1}; --- -2.38.0 - diff --git a/0003-build-Fix-error-during-out-of-tree-build.patch b/0003-build-Fix-error-during-out-of-tree-build.patch deleted file mode 100644 index f0bc23f..0000000 --- a/0003-build-Fix-error-during-out-of-tree-build.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 73dd2f99a6b174b696ba53c61e1c79b9edf9bc5b Mon Sep 17 00:00:00 2001 -From: Ben Brown -Date: Wed, 25 May 2022 16:26:13 +0100 -Subject: [PATCH] build: Fix error during out of tree build - -Fixes the following error: - - ../../libxtables/xtables.c:52:10: fatal error: libiptc/linux_list.h: No such file or directory - 52 | #include - -Fixes: f58b0d7406451 ("libxtables: Implement notargets hash table") -Signed-off-by: Ben Brown -Signed-off-by: Phil Sutter -(cherry picked from commit 0ebf52fc951b2a4d98a166afb34af4f364bbeece) ---- - libxtables/Makefile.am | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/libxtables/Makefile.am b/libxtables/Makefile.am -index 8ff6b0cad2850..3bfded8570e08 100644 ---- a/libxtables/Makefile.am -+++ b/libxtables/Makefile.am -@@ -1,7 +1,7 @@ - # -*- Makefile -*- - - AM_CFLAGS = ${regular_CFLAGS} --AM_CPPFLAGS = ${regular_CPPFLAGS} -I${top_builddir}/include -I${top_srcdir}/include -I${top_srcdir}/iptables ${kinclude_CPPFLAGS} -+AM_CPPFLAGS = ${regular_CPPFLAGS} -I${top_builddir}/include -I${top_srcdir}/include -I${top_srcdir}/iptables -I${top_srcdir} ${kinclude_CPPFLAGS} - - lib_LTLIBRARIES = libxtables.la - libxtables_la_SOURCES = xtables.c xtoptions.c getethertype.c --- -2.38.0 - diff --git a/0004-libxtables-Unexport-init_extensions-declarations.patch b/0004-libxtables-Unexport-init_extensions-declarations.patch deleted file mode 100644 index 1f31a72..0000000 --- a/0004-libxtables-Unexport-init_extensions-declarations.patch +++ /dev/null @@ -1,88 +0,0 @@ -From cde22a75ebb8e2d77b971c246cd1e83c341dbe61 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 1 Jun 2022 19:15:06 +0200 -Subject: [PATCH] libxtables: Unexport init_extensions*() declarations - -The functions are used for static builds to initialize extensions after -libxtables init. Regular library users should not need them, but the -empty declarations introduced in #else case (and therefore present in -user's env) may clash with existing symbol names. - -Avoid problems and guard the whole block declaring the function -prototypes and mangling extensions' _init functions by XTABLES_INTERNAL. - -Reported-by: Nick Hainke -Fixes: 6c689b639cf8e ("Simplify static build extension loading") -Signed-off-by: Phil Sutter -(cherry picked from commit ef108943f69a6e20533d58823740d3f0534ea8ec) ---- - include/xtables.h | 44 ++++++++++++++++++++++---------------------- - 1 file changed, 22 insertions(+), 22 deletions(-) - -diff --git a/include/xtables.h b/include/xtables.h -index c2694b7b28886..f1937f3ea0530 100644 ---- a/include/xtables.h -+++ b/include/xtables.h -@@ -585,27 +585,6 @@ static inline void xtables_print_mark_mask(unsigned int mark, - xtables_print_val_mask(mark, mask, NULL); - } - --#if defined(ALL_INCLUSIVE) || defined(NO_SHARED_LIBS) --# ifdef _INIT --# undef _init --# define _init _INIT --# endif -- extern void init_extensions(void); -- extern void init_extensions4(void); -- extern void init_extensions6(void); -- extern void init_extensionsa(void); -- extern void init_extensionsb(void); --#else --# define _init __attribute__((constructor)) _INIT --# define EMPTY_FUNC_DEF(x) static inline void x(void) {} -- EMPTY_FUNC_DEF(init_extensions) -- EMPTY_FUNC_DEF(init_extensions4) -- EMPTY_FUNC_DEF(init_extensions6) -- EMPTY_FUNC_DEF(init_extensionsa) -- EMPTY_FUNC_DEF(init_extensionsb) --# undef EMPTY_FUNC_DEF --#endif -- - extern const struct xtables_pprot xtables_chain_protos[]; - extern uint16_t xtables_parse_protocol(const char *s); - -@@ -663,9 +642,30 @@ void xtables_announce_chain(const char *name); - # define ARRAY_SIZE(x) (sizeof(x) / sizeof(*(x))) - # endif - -+#if defined(ALL_INCLUSIVE) || defined(NO_SHARED_LIBS) -+# ifdef _INIT -+# undef _init -+# define _init _INIT -+# endif -+ extern void init_extensions(void); -+ extern void init_extensions4(void); -+ extern void init_extensions6(void); -+ extern void init_extensionsa(void); -+ extern void init_extensionsb(void); -+#else -+# define _init __attribute__((constructor)) _INIT -+# define EMPTY_FUNC_DEF(x) static inline void x(void) {} -+ EMPTY_FUNC_DEF(init_extensions) -+ EMPTY_FUNC_DEF(init_extensions4) -+ EMPTY_FUNC_DEF(init_extensions6) -+ EMPTY_FUNC_DEF(init_extensionsa) -+ EMPTY_FUNC_DEF(init_extensionsb) -+# undef EMPTY_FUNC_DEF -+#endif -+ - extern void _init(void); - --#endif -+#endif /* XTABLES_INTERNAL */ - - #ifdef __cplusplus - } /* extern "C" */ --- -2.38.0 - diff --git a/0005-iptables-legacy-Drop-redundant-include-of-xtables-mu.patch b/0005-iptables-legacy-Drop-redundant-include-of-xtables-mu.patch deleted file mode 100644 index 8c391fd..0000000 --- a/0005-iptables-legacy-Drop-redundant-include-of-xtables-mu.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 00395b5347f0addcd4192cd8936dafed1ef1930b Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 1 Jun 2022 19:29:28 +0200 -Subject: [PATCH] iptables-legacy: Drop redundant include of xtables-multi.h - -The header is included unconditionally first, so no point in doing it a -second time of ENABLE_NFTABLES is defined. - -Fixes: be70918eab26e ("xtables: rename xt-multi binaries to -nft, -legacy") -Signed-off-by: Phil Sutter -(cherry picked from commit ef5d0c68261611d72ccecb3ae05c24448fbc91f5) ---- - iptables/xtables-legacy-multi.c | 4 ---- - 1 file changed, 4 deletions(-) - -diff --git a/iptables/xtables-legacy-multi.c b/iptables/xtables-legacy-multi.c -index 3b7905ff76b13..2c71931551b5c 100644 ---- a/iptables/xtables-legacy-multi.c -+++ b/iptables/xtables-legacy-multi.c -@@ -14,10 +14,6 @@ - #include "ip6tables-multi.h" - #endif - --#ifdef ENABLE_NFTABLES --#include "xtables-multi.h" --#endif -- - static const struct subcommand multi_subcommands[] = { - #ifdef ENABLE_IPV4 - {"iptables", iptables_main}, --- -2.38.0 - diff --git a/0006-extensions-string-Do-not-print-default-to-value.patch b/0006-extensions-string-Do-not-print-default-to-value.patch deleted file mode 100644 index 3bffb15..0000000 --- a/0006-extensions-string-Do-not-print-default-to-value.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 0e97017c45a6135c1b49537c9f9c6ea25b091157 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 8 Jun 2022 13:28:10 +0200 -Subject: [PATCH] extensions: string: Do not print default --to value - -Default value is UINT16_MAX, not 0. Fix the conditional printing. - -Fixes: c6fbf41cdd157 ("update string match to reflect new kernel implementation (Pablo Neira)") -Signed-off-by: Phil Sutter -(cherry picked from commit 1bfb1d916e467e2bcbc44ce1a50a2be5c12b7ef8) ---- - extensions/libxt_string.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/extensions/libxt_string.c b/extensions/libxt_string.c -index 739a8e7fd66b6..da05fad0f59c8 100644 ---- a/extensions/libxt_string.c -+++ b/extensions/libxt_string.c -@@ -269,7 +269,7 @@ string_print(const void *ip, const struct xt_entry_match *match, int numeric) - printf(" ALGO name %s", info->algo); - if (info->from_offset != 0) - printf(" FROM %u", info->from_offset); -- if (info->to_offset != 0) -+ if (info->to_offset != UINT16_MAX) - printf(" TO %u", info->to_offset); - if (revision > 0 && info->u.v1.flags & XT_STRING_FLAG_IGNORECASE) - printf(" ICASE"); -@@ -293,7 +293,7 @@ static void string_save(const void *ip, const struct xt_entry_match *match) - printf(" --algo %s", info->algo); - if (info->from_offset != 0) - printf(" --from %u", info->from_offset); -- if (info->to_offset != 0) -+ if (info->to_offset != UINT16_MAX) - printf(" --to %u", info->to_offset); - if (revision > 0 && info->u.v1.flags & XT_STRING_FLAG_IGNORECASE) - printf(" --icase"); --- -2.38.0 - diff --git a/0007-nft-Exit-if-nftnl_alloc_expr-fails.patch b/0007-nft-Exit-if-nftnl_alloc_expr-fails.patch deleted file mode 100644 index e1cf52f..0000000 --- a/0007-nft-Exit-if-nftnl_alloc_expr-fails.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 1d9bcea2e0ba5e3015ed8d605d5921fb6954110d Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 14 Jun 2022 17:44:47 +0200 -Subject: [PATCH] nft: Exit if nftnl_alloc_expr fails - -In some code-paths, 'reg' pointer remaining uninitialized is used later -so at least minimal error checking is necessary. Given that a call to -nftnl_alloc_expr() with sane argument should never fail, complain and -exit if it happens. - -Fixes: 7e38890c6b4fb ("nft: prepare for dynamic register allocation") -Signed-off-by: Phil Sutter -(cherry picked from commit 2ce0014750c0afc06a87479462746ed113736025) ---- - iptables/nft-shared.c | 31 ++++++++++++++++--------------- - 1 file changed, 16 insertions(+), 15 deletions(-) - -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 27e95c1ae4f38..74e19ccad226d 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -40,15 +40,24 @@ extern struct nft_family_ops nft_family_ops_ipv6; - extern struct nft_family_ops nft_family_ops_arp; - extern struct nft_family_ops nft_family_ops_bridge; - -+static struct nftnl_expr *xt_nftnl_expr_alloc(const char *name) -+{ -+ struct nftnl_expr *expr = nftnl_expr_alloc(name); -+ -+ if (expr) -+ return expr; -+ -+ xtables_error(RESOURCE_PROBLEM, -+ "Failed to allocate nftnl expression '%s'", name); -+} -+ - void add_meta(struct nft_handle *h, struct nftnl_rule *r, uint32_t key, - uint8_t *dreg) - { - struct nftnl_expr *expr; - uint8_t reg; - -- expr = nftnl_expr_alloc("meta"); -- if (expr == NULL) -- return; -+ expr = xt_nftnl_expr_alloc("meta"); - - reg = NFT_REG_1; - nftnl_expr_set_u32(expr, NFTNL_EXPR_META_KEY, key); -@@ -64,9 +73,7 @@ void add_payload(struct nft_handle *h, struct nftnl_rule *r, - struct nftnl_expr *expr; - uint8_t reg; - -- expr = nftnl_expr_alloc("payload"); -- if (expr == NULL) -- return; -+ expr = xt_nftnl_expr_alloc("payload"); - - reg = NFT_REG_1; - nftnl_expr_set_u32(expr, NFTNL_EXPR_PAYLOAD_BASE, base); -@@ -85,9 +92,7 @@ void add_bitwise_u16(struct nft_handle *h, struct nftnl_rule *r, - struct nftnl_expr *expr; - uint8_t reg; - -- expr = nftnl_expr_alloc("bitwise"); -- if (expr == NULL) -- return; -+ expr = xt_nftnl_expr_alloc("bitwise"); - - reg = NFT_REG_1; - nftnl_expr_set_u32(expr, NFTNL_EXPR_BITWISE_SREG, sreg); -@@ -107,9 +112,7 @@ void add_bitwise(struct nft_handle *h, struct nftnl_rule *r, - uint32_t xor[4] = { 0 }; - uint8_t reg = *dreg; - -- expr = nftnl_expr_alloc("bitwise"); -- if (expr == NULL) -- return; -+ expr = xt_nftnl_expr_alloc("bitwise"); - - nftnl_expr_set_u32(expr, NFTNL_EXPR_BITWISE_SREG, sreg); - nftnl_expr_set_u32(expr, NFTNL_EXPR_BITWISE_DREG, reg); -@@ -126,9 +129,7 @@ void add_cmp_ptr(struct nftnl_rule *r, uint32_t op, void *data, size_t len, - { - struct nftnl_expr *expr; - -- expr = nftnl_expr_alloc("cmp"); -- if (expr == NULL) -- return; -+ expr = xt_nftnl_expr_alloc("cmp"); - - nftnl_expr_set_u32(expr, NFTNL_EXPR_CMP_SREG, sreg); - nftnl_expr_set_u32(expr, NFTNL_EXPR_CMP_OP, op); --- -2.38.0 - diff --git a/0008-xtables-monitor-add-missing-spaces-in-printed-str.patch b/0008-xtables-monitor-add-missing-spaces-in-printed-str.patch deleted file mode 100644 index 21ca0af..0000000 --- a/0008-xtables-monitor-add-missing-spaces-in-printed-str.patch +++ /dev/null @@ -1,45 +0,0 @@ -From e43a1d007cf4ca9bc5e642f9caafea8c14beb59f Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Anton=20Luka=20=C5=A0ijanec?= -Date: Wed, 22 Jun 2022 21:56:47 +0200 -Subject: [PATCH] xtables-monitor: add missing spaces in printed str -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -when printing the ID and OPTs in iptables/xtables-monitor.c, a space is -missing after the string, thereby concatenating the number with the next -item in the printed PACKET line. - -Fixes: d26c538b9a549 ("xtables: add xtables-monitor") -Signed-off-by: Anton Luka Šijanec -Signed-off-by: Phil Sutter -(cherry picked from commit 6c12201b5ff08d9e1524477ff63bb8810198d638) ---- - iptables/xtables-monitor.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/iptables/xtables-monitor.c b/iptables/xtables-monitor.c -index 905bb7fed6309..a1eba2f43407b 100644 ---- a/iptables/xtables-monitor.c -+++ b/iptables/xtables-monitor.c -@@ -339,7 +339,7 @@ static void trace_print_packet(const struct nftnl_trace *nlt, struct cb_arg *arg - inet_ntop(AF_INET, &iph->daddr, addrbuf, sizeof(addrbuf)); - printf("DST=%s ", addrbuf); - -- printf("LEN=%d TOS=0x%x TTL=%d ID=%d", ntohs(iph->tot_len), iph->tos, iph->ttl, ntohs(iph->id)); -+ printf("LEN=%d TOS=0x%x TTL=%d ID=%d ", ntohs(iph->tot_len), iph->tos, iph->ttl, ntohs(iph->id)); - if (iph->frag_off & htons(0x8000)) - printf("CE "); - if (iph->frag_off & htons(IP_DF)) -@@ -362,7 +362,7 @@ static void trace_print_packet(const struct nftnl_trace *nlt, struct cb_arg *arg - printf("OPT ("); - for (i = 0; i < optsize; i++) - printf("%02X", op[i]); -- printf(")"); -+ printf(") "); - } - break; - } --- -2.38.0 - diff --git a/0009-libxtables-Fix-unsupported-extension-warning-corner-.patch b/0009-libxtables-Fix-unsupported-extension-warning-corner-.patch deleted file mode 100644 index 14116b1..0000000 --- a/0009-libxtables-Fix-unsupported-extension-warning-corner-.patch +++ /dev/null @@ -1,91 +0,0 @@ -From aca74d2dab47f74a01af8092772a6005fa06e9c6 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 30 Jun 2022 18:04:39 +0200 -Subject: [PATCH] libxtables: Fix unsupported extension warning corner case - -Some extensions are not supported in revision 0 by user space anymore, -for those the warning in xtables_compatible_revision() does not print as -no revision 0 is tried. - -To fix this, one has to track if none of the user space supported -revisions were accepted by the kernel. Therefore add respective logic to -xtables_find_{target,match}(). - -Note that this does not lead to duplicated warnings for unsupported -extensions that have a revision 0 because xtables_compatible_revision() -returns true for them to allow for extension's help output. - -For the record, these ip6tables extensions are affected: set/SET, -socket, tos/TOS, TPROXY and SNAT. In addition to that, TEE is affected -for both families. - -Fixes: 17534cb18ed0a ("Improve error messages for unsupported extensions") -Signed-off-by: Phil Sutter -(cherry picked from commit 552c4a2f9e5706fef5f7abb27d1492a78bbb2a37) ---- - libxtables/xtables.c | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/libxtables/xtables.c b/libxtables/xtables.c -index 0638f9271c601..d9023950ca419 100644 ---- a/libxtables/xtables.c -+++ b/libxtables/xtables.c -@@ -777,6 +777,7 @@ xtables_find_match(const char *name, enum xtables_tryload tryload, - struct xtables_match *ptr; - const char *icmp6 = "icmp6"; - bool found = false; -+ bool seen = false; - - if (strlen(name) >= XT_EXTENSION_MAXNAMELEN) - xtables_error(PARAMETER_PROBLEM, -@@ -795,6 +796,7 @@ xtables_find_match(const char *name, enum xtables_tryload tryload, - if (extension_cmp(name, (*dptr)->name, (*dptr)->family)) { - ptr = *dptr; - *dptr = (*dptr)->next; -+ seen = true; - if (!found && - xtables_fully_register_pending_match(ptr, prev)) { - found = true; -@@ -808,6 +810,11 @@ xtables_find_match(const char *name, enum xtables_tryload tryload, - dptr = &((*dptr)->next); - } - -+ if (seen && !found) -+ fprintf(stderr, -+ "Warning: Extension %s is not supported, missing kernel module?\n", -+ name); -+ - for (ptr = xtables_matches; ptr; ptr = ptr->next) { - if (extension_cmp(name, ptr->name, ptr->family)) { - struct xtables_match *clone; -@@ -900,6 +907,7 @@ xtables_find_target(const char *name, enum xtables_tryload tryload) - struct xtables_target **dptr; - struct xtables_target *ptr; - bool found = false; -+ bool seen = false; - - /* Standard target? */ - if (strcmp(name, "") == 0 -@@ -918,6 +926,7 @@ xtables_find_target(const char *name, enum xtables_tryload tryload) - if (extension_cmp(name, (*dptr)->name, (*dptr)->family)) { - ptr = *dptr; - *dptr = (*dptr)->next; -+ seen = true; - if (!found && - xtables_fully_register_pending_target(ptr, prev)) { - found = true; -@@ -931,6 +940,11 @@ xtables_find_target(const char *name, enum xtables_tryload tryload) - dptr = &((*dptr)->next); - } - -+ if (seen && !found) -+ fprintf(stderr, -+ "Warning: Extension %s is not supported, missing kernel module?\n", -+ name); -+ - for (ptr = xtables_targets; ptr; ptr = ptr->next) { - if (extension_cmp(name, ptr->name, ptr->family)) { - struct xtables_target *clone; --- -2.38.0 - diff --git a/0010-nft-fix-ebtables-among-match-when-mac-ip-addresses-a.patch b/0010-nft-fix-ebtables-among-match-when-mac-ip-addresses-a.patch deleted file mode 100644 index b27ae9a..0000000 --- a/0010-nft-fix-ebtables-among-match-when-mac-ip-addresses-a.patch +++ /dev/null @@ -1,36 +0,0 @@ -From ec682793d218eadd655c7c279abc680eb1f11738 Mon Sep 17 00:00:00 2001 -From: Florian Westphal -Date: Tue, 2 Aug 2022 14:52:30 +0200 -Subject: [PATCH] nft: fix ebtables among match when mac+ip addresses are used - -When matching mac and ip addresses, the ip address needs to be placed -into then 2nd 32bit register, the switch to dynamic register allocation -instead re-uses reg1, this partially clobbers the mac address, so -set lookup comes up empty even though it should find a match. - -Fixes: 7e38890c6b4fb ("nft: prepare for dynamic register allocation") -Reported-by: Yi Chen -Signed-off-by: Florian Westphal -(cherry picked from commit 2ba74d421cd622757df7a93720afc3b5b4b3b4e0) ---- - iptables/nft.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/iptables/nft.c b/iptables/nft.c -index ec79f2bc5e98b..ee003511ab7f3 100644 ---- a/iptables/nft.c -+++ b/iptables/nft.c -@@ -1208,8 +1208,8 @@ static int __add_nft_among(struct nft_handle *h, const char *table, - nftnl_rule_add_expr(r, e); - - if (ip) { -- e = gen_payload(h, NFT_PAYLOAD_NETWORK_HEADER, ip_addr_off[dst], -- sizeof(struct in_addr), ®); -+ e = __gen_payload(NFT_PAYLOAD_NETWORK_HEADER, ip_addr_off[dst], -+ sizeof(struct in_addr), NFT_REG32_02); - if (!e) - return -ENOMEM; - nftnl_rule_add_expr(r, e); --- -2.38.0 - diff --git a/0011-ebtables-Drop-unused-OPT_-defines.patch b/0011-ebtables-Drop-unused-OPT_-defines.patch deleted file mode 100644 index 1e5c5ae..0000000 --- a/0011-ebtables-Drop-unused-OPT_-defines.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 658804938d308b530ff127b09745acb97653afe4 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 27 Sep 2022 18:53:50 +0200 -Subject: [PATCH] ebtables: Drop unused OPT_* defines - -Obviously copied from legacy ebtables, not needed by ebtables-nft. -OPT_CNT_* ones seem not even used in legacy anymore. - -Signed-off-by: Phil Sutter -(cherry picked from commit e8fce1d700d068f7cebf009ee02b85623be2d4c4) ---- - iptables/xtables-eb.c | 3 --- - 1 file changed, 3 deletions(-) - -diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c -index 3d15063e80e91..fbf2b42bfcf17 100644 ---- a/iptables/xtables-eb.c -+++ b/iptables/xtables-eb.c -@@ -168,10 +168,7 @@ int ebt_get_current_chain(const char *chain) - #define OPT_ZERO 0x100 - #define OPT_LOGICALIN 0x200 - #define OPT_LOGICALOUT 0x400 --#define OPT_KERNELDATA 0x800 /* This value is also defined in ebtablesd.c */ - #define OPT_COUNT 0x1000 /* This value is also defined in libebtc.c */ --#define OPT_CNT_INCR 0x2000 /* This value is also defined in libebtc.c */ --#define OPT_CNT_DECR 0x4000 /* This value is also defined in libebtc.c */ - - /* Default command line options. Do not mess around with the already - * assigned numbers unless you know what you are doing */ --- -2.38.0 - diff --git a/0012-ebtables-Eliminate-OPT_TABLE.patch b/0012-ebtables-Eliminate-OPT_TABLE.patch deleted file mode 100644 index bac5df2..0000000 --- a/0012-ebtables-Eliminate-OPT_TABLE.patch +++ /dev/null @@ -1,46 +0,0 @@ -From 61a15a6189bd1ebfe0632c4f60f2510b5ac42e89 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 27 Sep 2022 19:03:47 +0200 -Subject: [PATCH] ebtables: Eliminate OPT_TABLE - -The flag is used for duplicate option checking only and there is a -boolean indicating the same already. So copy the error message from -EBT_CHECK_OPTION() in situ and just take care not to disturb restore -mode handling. - -Signed-off-by: Phil Sutter -(cherry picked from commit 39cc849ed0f7ae0e5e09e3a2c278708fd36c8c14) ---- - iptables/xtables-eb.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c -index fbf2b42bfcf17..c0bf1764fd710 100644 ---- a/iptables/xtables-eb.c -+++ b/iptables/xtables-eb.c -@@ -158,7 +158,6 @@ int ebt_get_current_chain(const char *chain) - #define OPT_COMMANDS (flags & OPT_COMMAND || flags & OPT_ZERO) - - #define OPT_COMMAND 0x01 --#define OPT_TABLE 0x02 - #define OPT_IN 0x04 - #define OPT_OUT 0x08 - #define OPT_JUMP 0x10 -@@ -894,11 +893,13 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - } - break; - case 't': /* Table */ -- ebt_check_option2(&flags, OPT_TABLE); - if (restore && table_set) - xtables_error(PARAMETER_PROBLEM, - "The -t option cannot be used in %s.\n", - xt_params->program_name); -+ else if (table_set) -+ xtables_error(PARAMETER_PROBLEM, -+ "Multiple use of same option not allowed"); - if (!nft_table_builtin_find(h, optarg)) - xtables_error(VERSION_PROBLEM, - "table '%s' does not exist", --- -2.38.0 - diff --git a/0013-ebtables-Merge-OPT_-flags-with-xshared-ones.patch b/0013-ebtables-Merge-OPT_-flags-with-xshared-ones.patch deleted file mode 100644 index b1c8c7d..0000000 --- a/0013-ebtables-Merge-OPT_-flags-with-xshared-ones.patch +++ /dev/null @@ -1,100 +0,0 @@ -From 4b4538ad6ffd40c46e10d2ea8dbb6d8e819a3e26 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 27 Sep 2022 19:46:47 +0200 -Subject: [PATCH] ebtables: Merge OPT_* flags with xshared ones - -Despite also including xshared.h, xtables-eb.c defined its own OPT_* -flags with clashing values. Albeit ugly, this wasn't a problem in -practice until commit 51d9d9e081344 ("ebtables: Support verbose mode") -which introduced use of OPT_VERBOSE from xshared - with same value as -the local OPT_PROTOCOL define. - -Eliminate the clash by appending ebtables-specific flags to the xshared -enum and adjust for the different names of some others. - -Fixes: 51d9d9e081344 ("ebtables: Support verbose mode") -Signed-off-by: Phil Sutter -(cherry picked from commit db420e268735e8499ca16146234ace79a9f1128a) ---- - iptables/xshared.h | 5 +++++ - iptables/xtables-eb.c | 20 ++++---------------- - 2 files changed, 9 insertions(+), 16 deletions(-) - -diff --git a/iptables/xshared.h b/iptables/xshared.h -index 14568bb00fb65..e45ab660c03fb 100644 ---- a/iptables/xshared.h -+++ b/iptables/xshared.h -@@ -37,6 +37,11 @@ enum { - OPT_OPCODE = 1 << 15, - OPT_H_TYPE = 1 << 16, - OPT_P_TYPE = 1 << 17, -+ /* below are for ebtables only */ -+ OPT_LOGICALIN = 1 << 18, -+ OPT_LOGICALOUT = 1 << 19, -+ OPT_COMMAND = 1 << 20, -+ OPT_ZERO = 1 << 21, - }; - - #define NUMBER_OF_OPT ARRAY_SIZE(optflags) -diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c -index c0bf1764fd710..78e21a88fa519 100644 ---- a/iptables/xtables-eb.c -+++ b/iptables/xtables-eb.c -@@ -157,18 +157,6 @@ int ebt_get_current_chain(const char *chain) - /* Checks whether a command has already been specified */ - #define OPT_COMMANDS (flags & OPT_COMMAND || flags & OPT_ZERO) - --#define OPT_COMMAND 0x01 --#define OPT_IN 0x04 --#define OPT_OUT 0x08 --#define OPT_JUMP 0x10 --#define OPT_PROTOCOL 0x20 --#define OPT_SOURCE 0x40 --#define OPT_DEST 0x80 --#define OPT_ZERO 0x100 --#define OPT_LOGICALIN 0x200 --#define OPT_LOGICALOUT 0x400 --#define OPT_COUNT 0x1000 /* This value is also defined in libebtc.c */ -- - /* Default command line options. Do not mess around with the already - * assigned numbers unless you know what you are doing */ - struct option ebt_original_options[] = -@@ -923,7 +911,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - xtables_error(PARAMETER_PROBLEM, - "Command and option do not match"); - if (c == 'i') { -- ebt_check_option2(&flags, OPT_IN); -+ ebt_check_option2(&flags, OPT_VIANAMEIN); - if (selected_chain > 2 && selected_chain < NF_BR_BROUTING) - xtables_error(PARAMETER_PROBLEM, - "Use -i only in INPUT, FORWARD, PREROUTING and BROUTING chains"); -@@ -943,7 +931,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - ebtables_parse_interface(optarg, cs.eb.logical_in); - break; - } else if (c == 'o') { -- ebt_check_option2(&flags, OPT_OUT); -+ ebt_check_option2(&flags, OPT_VIANAMEOUT); - if (selected_chain < 2 || selected_chain == NF_BR_BROUTING) - xtables_error(PARAMETER_PROBLEM, - "Use -o only in OUTPUT, FORWARD and POSTROUTING chains"); -@@ -980,7 +968,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - cs.eb.bitmask |= EBT_SOURCEMAC; - break; - } else if (c == 'd') { -- ebt_check_option2(&flags, OPT_DEST); -+ ebt_check_option2(&flags, OPT_DESTINATION); - if (ebt_check_inverse2(optarg, argc, argv)) - cs.eb.invflags |= EBT_IDEST; - -@@ -991,7 +979,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - cs.eb.bitmask |= EBT_DESTMAC; - break; - } else if (c == 'c') { -- ebt_check_option2(&flags, OPT_COUNT); -+ ebt_check_option2(&flags, OPT_COUNTERS); - if (ebt_check_inverse2(optarg, argc, argv)) - xtables_error(PARAMETER_PROBLEM, - "Unexpected '!' after -c"); --- -2.38.0 - diff --git a/0014-extensions-among-Remove-pointless-fall-through.patch b/0014-extensions-among-Remove-pointless-fall-through.patch deleted file mode 100644 index 491d89d..0000000 --- a/0014-extensions-among-Remove-pointless-fall-through.patch +++ /dev/null @@ -1,36 +0,0 @@ -From 92e1b55ebb8c581e3551f7ef74c1f43e271b628e Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 29 Sep 2022 19:11:55 +0200 -Subject: [PATCH] extensions: among: Remove pointless fall through - -This seems to be a leftover from an earlier version of the switch(). -This fall through is never effective as the next case's code will never -apply. So just break instead. - -Fixes: 26753888720d8 ("nft: bridge: Rudimental among extension support") -Signed-off-by: Phil Sutter -(cherry picked from commit eafe731a50058ed59305ee4ab1ea2d63d6c4e86e) ---- - extensions/libebt_among.c | 5 ++--- - 1 file changed, 2 insertions(+), 3 deletions(-) - -diff --git a/extensions/libebt_among.c b/extensions/libebt_among.c -index 7eb898f984bba..c607a775539d3 100644 ---- a/extensions/libebt_among.c -+++ b/extensions/libebt_among.c -@@ -152,10 +152,9 @@ static int bramong_parse(int c, char **argv, int invert, - xtables_error(PARAMETER_PROBLEM, - "File should only contain one line"); - optarg[flen-1] = '\0'; -- /* fall through */ -+ break; - case AMONG_DST: -- if (c == AMONG_DST) -- dst = true; -+ dst = true; - /* fall through */ - case AMONG_SRC: - break; --- -2.38.0 - diff --git a/0015-extensions-among-Fix-for-use-with-ebtables-restore.patch b/0015-extensions-among-Fix-for-use-with-ebtables-restore.patch deleted file mode 100644 index df93cff..0000000 --- a/0015-extensions-among-Fix-for-use-with-ebtables-restore.patch +++ /dev/null @@ -1,57 +0,0 @@ -From 01838c9818bd7ddb25165f0a76b4b880f14c7c53 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 30 Sep 2022 17:51:55 +0200 -Subject: [PATCH] extensions: among: Fix for use with ebtables-restore - -When restoring multiple rules which use among match, new size may be -smaller than the old one which caused invalid writes by the memcpy() -call. Expect this and realloc the match only if it needs to grow. Also -use realloc instead of freeing and allocating from scratch. - -Fixes: 26753888720d8 ("nft: bridge: Rudimental among extension support") -Signed-off-by: Phil Sutter -(cherry picked from commit fca04aa7a53252464c289997e71de10189971da6) ---- - extensions/libebt_among.c | 14 ++++++-------- - 1 file changed, 6 insertions(+), 8 deletions(-) - -diff --git a/extensions/libebt_among.c b/extensions/libebt_among.c -index c607a775539d3..1eab201984408 100644 ---- a/extensions/libebt_among.c -+++ b/extensions/libebt_among.c -@@ -119,7 +119,6 @@ static int bramong_parse(int c, char **argv, int invert, - struct xt_entry_match **match) - { - struct nft_among_data *data = (struct nft_among_data *)(*match)->data; -- struct xt_entry_match *new_match; - bool have_ip, dst = false; - size_t new_size, cnt; - struct stat stats; -@@ -170,18 +169,17 @@ static int bramong_parse(int c, char **argv, int invert, - new_size *= sizeof(struct nft_among_pair); - new_size += XT_ALIGN(sizeof(struct xt_entry_match)) + - sizeof(struct nft_among_data); -- new_match = xtables_calloc(1, new_size); -- memcpy(new_match, *match, (*match)->u.match_size); -- new_match->u.match_size = new_size; - -- data = (struct nft_among_data *)new_match->data; -+ if (new_size > (*match)->u.match_size) { -+ *match = xtables_realloc(*match, new_size); -+ (*match)->u.match_size = new_size; -+ data = (struct nft_among_data *)(*match)->data; -+ } -+ - have_ip = nft_among_pairs_have_ip(optarg); - poff = nft_among_prepare_data(data, dst, cnt, invert, have_ip); - parse_nft_among_pairs(data->pairs + poff, optarg, cnt, have_ip); - -- free(*match); -- *match = new_match; -- - if (c == AMONG_DST_F || c == AMONG_SRC_F) { - munmap(argv, flen); - close(fd); --- -2.38.0 - diff --git a/0016-extensions-libebt_stp-Eliminate-duplicate-space-in-o.patch b/0016-extensions-libebt_stp-Eliminate-duplicate-space-in-o.patch deleted file mode 100644 index 4a3611c..0000000 --- a/0016-extensions-libebt_stp-Eliminate-duplicate-space-in-o.patch +++ /dev/null @@ -1,34 +0,0 @@ -From e95d770c4c69bf3c267421b3dec6724a31039ba6 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sat, 1 Oct 2022 00:15:35 +0200 -Subject: [PATCH] extensions: libebt_stp: Eliminate duplicate space in output - -No need for print_range() to print a trailing whitespace, caller does -this already. - -Fixes: fd8d7d7e5d911 ("ebtables-nft: add stp match") -Signed-off-by: Phil Sutter -(cherry picked from commit 262dff31a998ef8e2507bbfd9349d761769888da) ---- - extensions/libebt_stp.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/extensions/libebt_stp.c b/extensions/libebt_stp.c -index 3e9e24474eb61..41059baae7078 100644 ---- a/extensions/libebt_stp.c -+++ b/extensions/libebt_stp.c -@@ -146,9 +146,9 @@ static int parse_range(const char *portstring, void *lower, void *upper, - static void print_range(unsigned int l, unsigned int u) - { - if (l == u) -- printf("%u ", l); -+ printf("%u", l); - else -- printf("%u:%u ", l, u); -+ printf("%u:%u", l, u); - } - - static int --- -2.38.0 - diff --git a/0017-extensions-libip6t_dst-Fix-output-for-empty-options.patch b/0017-extensions-libip6t_dst-Fix-output-for-empty-options.patch deleted file mode 100644 index cd5b72c..0000000 --- a/0017-extensions-libip6t_dst-Fix-output-for-empty-options.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 4ad8c8cd1f8d39e49a5d33121f5e64ef1b3374f7 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sat, 1 Oct 2022 00:17:50 +0200 -Subject: [PATCH] extensions: libip6t_dst: Fix output for empty options - -If no --dst-opts were given, print_options() would print just a -whitespace. - -Fixes: 73866357e4a7a ("iptables: do not print trailing whitespaces") -Signed-off-by: Phil Sutter -(cherry picked from commit 11e06cbb3a87739a3d958ba4c2f08fea7b100a68) ---- - extensions/libip6t_dst.c | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/extensions/libip6t_dst.c b/extensions/libip6t_dst.c -index bf0e3e436665d..baa010f56ac22 100644 ---- a/extensions/libip6t_dst.c -+++ b/extensions/libip6t_dst.c -@@ -125,15 +125,15 @@ static void - print_options(unsigned int optsnr, uint16_t *optsp) - { - unsigned int i; -+ char sep = ' '; - -- printf(" "); - for(i = 0; i < optsnr; i++) { -- printf("%d", (optsp[i] & 0xFF00) >> 8); -+ printf("%c%d", sep, (optsp[i] & 0xFF00) >> 8); - - if ((optsp[i] & 0x00FF) != 0x00FF) - printf(":%d", (optsp[i] & 0x00FF)); - -- printf("%c", (i != optsnr - 1) ? ',' : ' '); -+ sep = ','; - } - } - --- -2.38.0 - diff --git a/0018-extensions-TCPOPTSTRIP-Do-not-print-empty-options.patch b/0018-extensions-TCPOPTSTRIP-Do-not-print-empty-options.patch deleted file mode 100644 index 07a7185..0000000 --- a/0018-extensions-TCPOPTSTRIP-Do-not-print-empty-options.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 024fa15ac7b508c26d1e013649dbb8cf57504e96 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sat, 1 Oct 2022 00:36:50 +0200 -Subject: [PATCH] extensions: TCPOPTSTRIP: Do not print empty options - -No point in printing anything if none of the bits are set. - -Fixes: aef4c1e727563 ("libxt_TCPOPTSTRIP") -Signed-off-by: Phil Sutter -(cherry picked from commit dba32a76aacf84181a9bd3ba1e301e59ab49d370) ---- - extensions/libxt_TCPOPTSTRIP.c | 13 +++++++++++++ - 1 file changed, 13 insertions(+) - -diff --git a/extensions/libxt_TCPOPTSTRIP.c b/extensions/libxt_TCPOPTSTRIP.c -index 6ea3489224602..ff873f98b3aaa 100644 ---- a/extensions/libxt_TCPOPTSTRIP.c -+++ b/extensions/libxt_TCPOPTSTRIP.c -@@ -142,6 +142,13 @@ tcpoptstrip_print_list(const struct xt_tcpoptstrip_target_info *info, - } - } - -+static bool tcpoptstrip_empty(const struct xt_tcpoptstrip_target_info *info) -+{ -+ static const struct xt_tcpoptstrip_target_info empty = {}; -+ -+ return memcmp(info, &empty, sizeof(empty)) == 0; -+} -+ - static void - tcpoptstrip_tg_print(const void *ip, const struct xt_entry_target *target, - int numeric) -@@ -149,6 +156,9 @@ tcpoptstrip_tg_print(const void *ip, const struct xt_entry_target *target, - const struct xt_tcpoptstrip_target_info *info = - (const void *)target->data; - -+ if (tcpoptstrip_empty(info)) -+ return; -+ - printf(" TCPOPTSTRIP options "); - tcpoptstrip_print_list(info, numeric); - } -@@ -159,6 +169,9 @@ tcpoptstrip_tg_save(const void *ip, const struct xt_entry_target *target) - const struct xt_tcpoptstrip_target_info *info = - (const void *)target->data; - -+ if (tcpoptstrip_empty(info)) -+ return; -+ - printf(" --strip-options "); - tcpoptstrip_print_list(info, true); - } --- -2.38.0 - diff --git a/0019-tests-IDLETIMER.t-Fix-syntax-support-for-restore-inp.patch b/0019-tests-IDLETIMER.t-Fix-syntax-support-for-restore-inp.patch deleted file mode 100644 index 485c144..0000000 --- a/0019-tests-IDLETIMER.t-Fix-syntax-support-for-restore-inp.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 273c8b704f12b4d35ca61088106d56d46f6229e6 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 30 Sep 2022 18:06:10 +0200 -Subject: [PATCH] tests: IDLETIMER.t: Fix syntax, support for restore input - -Expected output was wrong in the last OK test, probably defeating rule -search check. Also use a different label, otherwise the kernel will -reject the second idletimer with same label but different type if both -rules are added at once. - -Fixes: 85b9ec8615428 ("extensions: IDLETIMER: Add alarm timer option") -(cherry picked from commit de043bbf2b78cad83a639e27c75263aa478e8cc4) ---- - extensions/libxt_IDLETIMER.t | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/extensions/libxt_IDLETIMER.t b/extensions/libxt_IDLETIMER.t -index e8f306d2462c7..3345d5bef9e38 100644 ---- a/extensions/libxt_IDLETIMER.t -+++ b/extensions/libxt_IDLETIMER.t -@@ -2,4 +2,4 @@ - -j IDLETIMER --timeout;;FAIL - -j IDLETIMER --timeout 42;;FAIL - -j IDLETIMER --timeout 42 --label foo;=;OK ---j IDLETIMER --timeout 42 --label foo --alarm;;OK -+-j IDLETIMER --timeout 42 --label bar --alarm;=;OK --- -2.38.0 - diff --git a/0020-tests-libebt_stp.t-Drop-duplicate-whitespace.patch b/0020-tests-libebt_stp.t-Drop-duplicate-whitespace.patch deleted file mode 100644 index f0dbb54..0000000 --- a/0020-tests-libebt_stp.t-Drop-duplicate-whitespace.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 79bd6688de0b4fc75549819340c5492c7f3fdb7c Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 5 Oct 2022 20:29:36 +0200 -Subject: [PATCH] tests: libebt_stp.t: Drop duplicate whitespace - -Code was fixed but the testcase adjustment slipped through. - -Fixes: 262dff31a998e ("extensions: libebt_stp: Eliminate duplicate space in output") -(cherry picked from commit dafb31980c4469fd28964b9703d3c77433cc7d21) ---- - extensions/libebt_stp.t | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/extensions/libebt_stp.t b/extensions/libebt_stp.t -index 0c6b77b91454b..17d6c1c0978e3 100644 ---- a/extensions/libebt_stp.t -+++ b/extensions/libebt_stp.t -@@ -1,7 +1,7 @@ - :INPUT,FORWARD,OUTPUT - --stp-type 1;=;OK - --stp-flags 0x1;--stp-flags topology-change -j CONTINUE;OK ----stp-root-prio 1 -j ACCEPT;=;OK -+--stp-root-prio 1 -j ACCEPT;=;OK - --stp-root-addr 0d:ea:d0:0b:ee:f0;=;OK - --stp-root-cost 1;=;OK - --stp-sender-prio 1;=;OK --- -2.38.0 - diff --git a/0021-libiptc-Fix-for-segfault-when-renaming-a-chain.patch b/0021-libiptc-Fix-for-segfault-when-renaming-a-chain.patch deleted file mode 100644 index aa7b7a7..0000000 --- a/0021-libiptc-Fix-for-segfault-when-renaming-a-chain.patch +++ /dev/null @@ -1,67 +0,0 @@ -From 6d9411d345bbfc7085cfd021b91f70933c13a68a Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 7 Oct 2022 18:29:07 +0200 -Subject: [PATCH] libiptc: Fix for segfault when renaming a chain - -This is an odd bug: If the number of chains is right and one renames the -last one in the list, libiptc dereferences a NULL pointer. Add fix and -test case for it. - -Fixes: 64ff47cde38e4 ("libiptc: fix chain rename bug in libiptc") -Reported-by: Julien Castets -Signed-off-by: Phil Sutter -(cherry picked from commit 97bf4e68fc0794adba3243fd96f40f4568e7216f) ---- - .../testcases/chain/0006rename-segfault_0 | 19 +++++++++++++++++++ - libiptc/libiptc.c | 9 +++++++++ - 2 files changed, 28 insertions(+) - create mode 100755 iptables/tests/shell/testcases/chain/0006rename-segfault_0 - -diff --git a/iptables/tests/shell/testcases/chain/0006rename-segfault_0 b/iptables/tests/shell/testcases/chain/0006rename-segfault_0 -new file mode 100755 -index 0000000000000..c10a8006b56b4 ---- /dev/null -+++ b/iptables/tests/shell/testcases/chain/0006rename-segfault_0 -@@ -0,0 +1,19 @@ -+#!/bin/bash -+# -+# Cover for a bug in libiptc: -+# - the chain 'node-98-tmp' is the last in the list sorted by name -+# - there are 81 chains in total, so three chain index buckets -+# - the last index bucket contains only the 'node-98-tmp' chain -+# => rename temporarily removes it from the bucket, leaving a NULL bucket -+# behind which is dereferenced later when inserting the chain again with new -+# name again -+ -+( -+ echo "*filter" -+ for chain in node-1 node-10 node-101 node-102 node-104 node-107 node-11 node-12 node-13 node-14 node-15 node-16 node-17 node-18 node-19 node-2 node-20 node-21 node-22 node-23 node-25 node-26 node-27 node-28 node-29 node-3 node-30 node-31 node-32 node-33 node-34 node-36 node-37 node-39 node-4 node-40 node-41 node-42 node-43 node-44 node-45 node-46 node-47 node-48 node-49 node-5 node-50 node-51 node-53 node-54 node-55 node-56 node-57 node-58 node-59 node-6 node-60 node-61 node-62 node-63 node-64 node-65 node-66 node-68 node-69 node-7 node-70 node-71 node-74 node-75 node-76 node-8 node-80 node-81 node-86 node-89 node-9 node-92 node-93 node-95 node-98-tmp; do -+ echo ":$chain - [0:0]" -+ done -+ echo "COMMIT" -+) | $XT_MULTI iptables-restore -+$XT_MULTI iptables -E node-98-tmp node-98 -+exit $? -diff --git a/libiptc/libiptc.c b/libiptc/libiptc.c -index ceeb017b39400..97823f935d1ee 100644 ---- a/libiptc/libiptc.c -+++ b/libiptc/libiptc.c -@@ -606,6 +606,15 @@ static int iptcc_chain_index_delete_chain(struct chain_head *c, struct xtc_handl - - if (index_ptr == &c->list) { /* Chain used as index ptr */ - -+ /* If this is the last chain in the list, its index bucket just -+ * became empty. Adjust the size to avoid a NULL-pointer deref -+ * later. -+ */ -+ if (next == &h->chains) { -+ h->chain_index_sz--; -+ return 0; -+ } -+ - /* See if its possible to avoid a rebuild, by shifting - * to next pointer. Its possible if the next pointer - * is located in the same index bucket. --- -2.38.0 - diff --git a/0022-extensions-DNAT-Fix-bad-IP-address-error-reporting.patch b/0022-extensions-DNAT-Fix-bad-IP-address-error-reporting.patch deleted file mode 100644 index 0da82e4..0000000 --- a/0022-extensions-DNAT-Fix-bad-IP-address-error-reporting.patch +++ /dev/null @@ -1,31 +0,0 @@ -From e1270cd849cec47ebce0b6abe1852f544d547824 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sun, 3 Jul 2022 15:59:19 +0200 -Subject: [PATCH] extensions: DNAT: Fix bad IP address error reporting - -When introducing 'start' variable to cover for IPv6 addresses enclosed -in brackets, this single spot was missed. - -Fixes: 14d77c8aa29a7 ("extensions: Merge IPv4 and IPv6 DNAT targets") -Signed-off-by: Phil Sutter -(cherry picked from commit c3432977d9a5e6c5d8e835094dc8c466a5d64f03) ---- - extensions/libxt_DNAT.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/extensions/libxt_DNAT.c b/extensions/libxt_DNAT.c -index 5696d31f2b0c5..7bfefc7961fac 100644 ---- a/extensions/libxt_DNAT.c -+++ b/extensions/libxt_DNAT.c -@@ -197,7 +197,7 @@ parse_to(const char *orig_arg, bool portok, - - if (!inet_pton(family, start, &range->min_addr)) - xtables_error(PARAMETER_PROBLEM, -- "Bad IP address \"%s\"", arg); -+ "Bad IP address \"%s\"", start); - if (dash) { - if (!inet_pton(family, dash + 1, &range->max_addr)) - xtables_error(PARAMETER_PROBLEM, --- -2.38.0 - diff --git a/0023-extensions-libebt_mark-Fix-mark-target-xlate.patch b/0023-extensions-libebt_mark-Fix-mark-target-xlate.patch deleted file mode 100644 index 4fac4f4..0000000 --- a/0023-extensions-libebt_mark-Fix-mark-target-xlate.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 9fabdca03f0748d3509c583576674519a7265802 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 23 Nov 2022 03:35:34 +0100 -Subject: [PATCH] extensions: libebt_mark: Fix mark target xlate - -Target value is constructed setting all non-target bits to one instead -of zero. - -Fixes: 03ecffe6c2cc0 ("ebtables-compat: add initial translations") -Signed-off-by: Phil Sutter -(cherry picked from commit c6d7a1dd72a21e7f8f117eedb61bff5b94ef5f0c) ---- - extensions/libebt_mark.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/extensions/libebt_mark.c b/extensions/libebt_mark.c -index 423c5c9133d0d..40e49618e0215 100644 ---- a/extensions/libebt_mark.c -+++ b/extensions/libebt_mark.c -@@ -201,7 +201,7 @@ static int brmark_xlate(struct xt_xlate *xl, - return 0; - } - -- tmp = info->target & EBT_VERDICT_BITS; -+ tmp = info->target | ~EBT_VERDICT_BITS; - xt_xlate_add(xl, "0x%lx %s ", info->mark, brmark_verdict(tmp)); - return 1; - } --- -2.38.0 - diff --git a/0024-extensions-libebt_mark-Fix-xlate-test-case.patch b/0024-extensions-libebt_mark-Fix-xlate-test-case.patch deleted file mode 100644 index 5e52a7d..0000000 --- a/0024-extensions-libebt_mark-Fix-xlate-test-case.patch +++ /dev/null @@ -1,57 +0,0 @@ -From 1d764e7ba1775cebe10d5af1296851c69dc4cd75 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 11 Mar 2022 18:28:49 +0100 -Subject: [PATCH] extensions: libebt_mark: Fix xlate test case - -The false suffix effectively disabled this test file, but it also has -problems: Apart from brmark_xlate() printing 'meta mark' instead of just -'mark', target is printed in the wrong position (like with any other -target-possessing extension. - -Fixes: e67c08880961f ("ebtables-translate: add initial test cases") -Signed-off-by: Phil Sutter -(cherry picked from commit bc5f9d05dbf7d0a6c5256c63c492273c93ad3434) ---- - extensions/libebt_mark.txlate | 11 +++++++++++ - extensions/libebt_mark.xlate | 11 ----------- - 2 files changed, 11 insertions(+), 11 deletions(-) - create mode 100644 extensions/libebt_mark.txlate - delete mode 100644 extensions/libebt_mark.xlate - -diff --git a/extensions/libebt_mark.txlate b/extensions/libebt_mark.txlate -new file mode 100644 -index 0000000000000..7529302d9a444 ---- /dev/null -+++ b/extensions/libebt_mark.txlate -@@ -0,0 +1,11 @@ -+ebtables-translate -A INPUT --mark-set 42 -+nft add rule bridge filter INPUT meta mark set 0x2a accept counter -+ -+ebtables-translate -A INPUT --mark-or 42 --mark-target RETURN -+nft add rule bridge filter INPUT meta mark set meta mark or 0x2a return counter -+ -+ebtables-translate -A INPUT --mark-and 42 --mark-target ACCEPT -+nft add rule bridge filter INPUT meta mark set meta mark and 0x2a accept counter -+ -+ebtables-translate -A INPUT --mark-xor 42 --mark-target DROP -+nft add rule bridge filter INPUT meta mark set meta mark xor 0x2a drop counter -diff --git a/extensions/libebt_mark.xlate b/extensions/libebt_mark.xlate -deleted file mode 100644 -index e0982a1e8ebd7..0000000000000 ---- a/extensions/libebt_mark.xlate -+++ /dev/null -@@ -1,11 +0,0 @@ --ebtables-translate -A INPUT --mark-set 42 --nft add rule bridge filter INPUT mark set 0x2a counter -- --ebtables-translate -A INPUT --mark-or 42 --mark-target RETURN --nft add rule bridge filter INPUT mark set mark or 0x2a counter return -- --ebtables-translate -A INPUT --mark-and 42 --mark-target ACCEPT --nft add rule bridge filter INPUT mark set mark and 0x2a counter accept -- --ebtables-translate -A INPUT --mark-xor 42 --mark-target DROP --nft add rule bridge filter INPUT mark set mark xor 0x2a counter drop --- -2.38.0 - diff --git a/0025-extensions-libebt_redirect-Fix-xlate-return-code.patch b/0025-extensions-libebt_redirect-Fix-xlate-return-code.patch deleted file mode 100644 index d3d79f4..0000000 --- a/0025-extensions-libebt_redirect-Fix-xlate-return-code.patch +++ /dev/null @@ -1,30 +0,0 @@ -From af15f1e8732076a85dd1290c3ef432c152fe8783 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 16 Nov 2022 13:03:05 +0100 -Subject: [PATCH] extensions: libebt_redirect: Fix xlate return code - -The callback is supposed to return 1 on success, not 0. - -Fixes: 24ce7465056ae ("ebtables-compat: add redirect match extension") -Signed-off-by: Phil Sutter -(cherry picked from commit 8543b6f2f4a3a15a5ece7dd1b320b477ce36a8d5) ---- - extensions/libebt_redirect.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/extensions/libebt_redirect.c b/extensions/libebt_redirect.c -index 6e653997ee99e..4d4c7a02cea89 100644 ---- a/extensions/libebt_redirect.c -+++ b/extensions/libebt_redirect.c -@@ -86,7 +86,7 @@ static int brredir_xlate(struct xt_xlate *xl, - xt_xlate_add(xl, "meta set pkttype host"); - if (red->target != EBT_ACCEPT) - xt_xlate_add(xl, " %s ", brredir_verdict(red->target)); -- return 0; -+ return 1; - } - - static struct xtables_target brredirect_target = { --- -2.38.0 - diff --git a/0026-extensions-libipt_ttl-Sanitize-xlate-callback.patch b/0026-extensions-libipt_ttl-Sanitize-xlate-callback.patch deleted file mode 100644 index ffac3be..0000000 --- a/0026-extensions-libipt_ttl-Sanitize-xlate-callback.patch +++ /dev/null @@ -1,39 +0,0 @@ -From a50f2401415e6421237202f4412eb168ab3b0b23 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 16 Nov 2022 13:09:16 +0100 -Subject: [PATCH] extensions: libipt_ttl: Sanitize xlate callback - -Catch unexpected values in info->mode, also fix indenting. - -Fixes: 1b320a1a1dc1f ("extensions: libipt_ttl: Add translation to nft") -Signed-off-by: Phil Sutter -(cherry picked from commit 800bed28b2b7bbd931166c7426640ae619f03342) ---- - extensions/libipt_ttl.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/extensions/libipt_ttl.c b/extensions/libipt_ttl.c -index 6bdd219618091..86ba554ef92a8 100644 ---- a/extensions/libipt_ttl.c -+++ b/extensions/libipt_ttl.c -@@ -106,7 +106,7 @@ static int ttl_xlate(struct xt_xlate *xl, - const struct ipt_ttl_info *info = - (struct ipt_ttl_info *) params->match->data; - -- switch (info->mode) { -+ switch (info->mode) { - case IPT_TTL_EQ: - xt_xlate_add(xl, "ip ttl"); - break; -@@ -121,7 +121,7 @@ static int ttl_xlate(struct xt_xlate *xl, - break; - default: - /* Should not happen. */ -- break; -+ return 0; - } - - xt_xlate_add(xl, " %u", info->ttl); --- -2.38.0 - diff --git a/0027-extensions-CONNMARK-Fix-xlate-callback.patch b/0027-extensions-CONNMARK-Fix-xlate-callback.patch deleted file mode 100644 index 58e1415..0000000 --- a/0027-extensions-CONNMARK-Fix-xlate-callback.patch +++ /dev/null @@ -1,88 +0,0 @@ -From 0928377e06e39a5ba7ea880b4a839a49e0e41dd0 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 17 Nov 2022 15:30:11 +0100 -Subject: [PATCH] extensions: CONNMARK: Fix xlate callback - -Bail out if nfmask != ctmask with XT_CONNMARK_SAVE and -XT_CONNMARK_RESTORE. Looks like this needs a similar implementation to -the one for XT_CONNMARK_SET. - -Fix shift mark translation: xt_connmark_shift_ops does not contain -useful strings for nftables. Also add needed braces around the term -being shifted. - -Fixes: db7b4e0de960c ("extensions: libxt_CONNMARK: Support bit-shifting for --restore,set and save-mark") -Signed-off-by: Phil Sutter -(cherry picked from commit e6747f6b1098b2bc7dfd482f287b3f90b351f164) ---- - extensions/libxt_CONNMARK.c | 15 ++++++++++----- - extensions/libxt_CONNMARK.txlate | 3 +++ - 2 files changed, 13 insertions(+), 5 deletions(-) - -diff --git a/extensions/libxt_CONNMARK.c b/extensions/libxt_CONNMARK.c -index 21e1091386294..a6568c99b6c4d 100644 ---- a/extensions/libxt_CONNMARK.c -+++ b/extensions/libxt_CONNMARK.c -@@ -595,11 +595,11 @@ static int connmark_tg_xlate_v2(struct xt_xlate *xl, - { - const struct xt_connmark_tginfo2 *info = - (const void *)params->target->data; -- const char *shift_op = xt_connmark_shift_ops[info->shift_dir]; -+ const char *braces = info->shift_bits ? "( " : ""; - - switch (info->mode) { - case XT_CONNMARK_SET: -- xt_xlate_add(xl, "ct mark set "); -+ xt_xlate_add(xl, "ct mark set %s", braces); - if (info->ctmask == 0xFFFFFFFFU) - xt_xlate_add(xl, "0x%x ", info->ctmark); - else if (info->ctmark == 0) -@@ -615,26 +615,31 @@ static int connmark_tg_xlate_v2(struct xt_xlate *xl, - info->ctmark, ~info->ctmask); - break; - case XT_CONNMARK_SAVE: -- xt_xlate_add(xl, "ct mark set mark"); -+ xt_xlate_add(xl, "ct mark set %smark", braces); - if (!(info->nfmask == UINT32_MAX && - info->ctmask == UINT32_MAX)) { - if (info->nfmask == info->ctmask) - xt_xlate_add(xl, " and 0x%x", info->nfmask); -+ else -+ return 0; - } - break; - case XT_CONNMARK_RESTORE: -- xt_xlate_add(xl, "meta mark set ct mark"); -+ xt_xlate_add(xl, "meta mark set %sct mark", braces); - if (!(info->nfmask == UINT32_MAX && - info->ctmask == UINT32_MAX)) { - if (info->nfmask == info->ctmask) - xt_xlate_add(xl, " and 0x%x", info->nfmask); -+ else -+ return 0; - } - break; - } - - if (info->mode <= XT_CONNMARK_RESTORE && - info->shift_bits != 0) { -- xt_xlate_add(xl, " %s %u", shift_op, info->shift_bits); -+ xt_xlate_add(xl, " ) %s %u", -+ info->shift_dir ? ">>" : "<<", info->shift_bits); - } - - return 1; -diff --git a/extensions/libxt_CONNMARK.txlate b/extensions/libxt_CONNMARK.txlate -index ce40ae5ea65e0..99627c2b05d45 100644 ---- a/extensions/libxt_CONNMARK.txlate -+++ b/extensions/libxt_CONNMARK.txlate -@@ -18,3 +18,6 @@ nft add rule ip mangle PREROUTING counter ct mark set mark - - iptables-translate -t mangle -A PREROUTING -j CONNMARK --restore-mark - nft add rule ip mangle PREROUTING counter meta mark set ct mark -+ -+iptables-translate -t mangle -A PREROUTING -j CONNMARK --set-mark 0x23/0x42 --right-shift-mark 5 -+nft add rule ip mangle PREROUTING counter ct mark set ( ct mark xor 0x23 and 0xffffff9c ) >> 5 --- -2.38.0 - diff --git a/0028-extensions-MARK-Sanitize-MARK_xlate.patch b/0028-extensions-MARK-Sanitize-MARK_xlate.patch deleted file mode 100644 index 3d72373..0000000 --- a/0028-extensions-MARK-Sanitize-MARK_xlate.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 841edd7c77ae23bb5966f5622cb3ab7e51f2642d Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 17 Nov 2022 16:01:11 +0100 -Subject: [PATCH] extensions: MARK: Sanitize MARK_xlate() - -Since markinfo->mode might contain unexpected values, add a default case -returning zero. - -Fixes: afefc7a134ca0 ("extensions: libxt_MARK: Add translation for revision 1 to nft") -Signed-off-by: Phil Sutter -(cherry picked from commit c4fc6440a6f39606e38744bfc827852bb68829f4) ---- - extensions/libxt_MARK.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/extensions/libxt_MARK.c b/extensions/libxt_MARK.c -index 1536563d0f4c7..100f6a38996ac 100644 ---- a/extensions/libxt_MARK.c -+++ b/extensions/libxt_MARK.c -@@ -366,6 +366,8 @@ static int MARK_xlate(struct xt_xlate *xl, - case XT_MARK_OR: - xt_xlate_add(xl, "mark or 0x%x ", (uint32_t)markinfo->mark); - break; -+ default: -+ return 0; - } - - return 1; --- -2.38.0 - diff --git a/0029-extensions-TCPMSS-Use-xlate-callback-for-IPv6-too.patch b/0029-extensions-TCPMSS-Use-xlate-callback-for-IPv6-too.patch deleted file mode 100644 index 0e32fcd..0000000 --- a/0029-extensions-TCPMSS-Use-xlate-callback-for-IPv6-too.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 6f8a39ec0045b5b60a00bccac0991989fc7b57af Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 17 Nov 2022 16:06:46 +0100 -Subject: [PATCH] extensions: TCPMSS: Use xlate callback for IPv6, too - -Data structures are identical and the translation is layer3-agnostic. - -Fixes: bebce197adb42 ("iptables: iptables-compat translation for TCPMSS") -Signed-off-by: Phil Sutter -(cherry picked from commit e05d9af176cb2a62c1bd24fa1d82b12a8ad00221) ---- - extensions/libxt_TCPMSS.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/extensions/libxt_TCPMSS.c b/extensions/libxt_TCPMSS.c -index 0d9b200ebc72f..251a5532a838b 100644 ---- a/extensions/libxt_TCPMSS.c -+++ b/extensions/libxt_TCPMSS.c -@@ -131,6 +131,7 @@ static struct xtables_target tcpmss_tg_reg[] = { - .x6_parse = TCPMSS_parse, - .x6_fcheck = TCPMSS_check, - .x6_options = TCPMSS6_opts, -+ .xlate = TCPMSS_xlate, - }, - }; - --- -2.38.0 - diff --git a/0030-extensions-TOS-Fix-v1-xlate-callback.patch b/0030-extensions-TOS-Fix-v1-xlate-callback.patch deleted file mode 100644 index 66aa817..0000000 --- a/0030-extensions-TOS-Fix-v1-xlate-callback.patch +++ /dev/null @@ -1,95 +0,0 @@ -From 3163d768164c897049ab1b76885593fb90fe94e0 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 17 Nov 2022 16:10:14 +0100 -Subject: [PATCH] extensions: TOS: Fix v1 xlate callback - -Translation entirely ignored tos_mask field. - -Fixes: b669e18489709 ("extensions: libxt_TOS: Add translation to nft") -Signed-off-by: Phil Sutter -(cherry picked from commit 161fb8ad126d8f330c8f59a4a1b5885d26477664) ---- - extensions/libxt_TOS.c | 33 +++++++++++++++++++++++---------- - extensions/libxt_TOS.txlate | 9 ++++++--- - 2 files changed, 29 insertions(+), 13 deletions(-) - -diff --git a/extensions/libxt_TOS.c b/extensions/libxt_TOS.c -index b66fa329f4150..4fc849bd2468b 100644 ---- a/extensions/libxt_TOS.c -+++ b/extensions/libxt_TOS.c -@@ -183,28 +183,41 @@ static void tos_tg_save(const void *ip, const struct xt_entry_target *target) - printf(" --set-tos 0x%02x/0x%02x", info->tos_value, info->tos_mask); - } - -+static int __tos_xlate(struct xt_xlate *xl, const char *ip, -+ uint8_t tos, uint8_t tosmask) -+{ -+ xt_xlate_add(xl, "%s dscp set ", ip); -+ if ((tosmask & 0x3f) == 0x3f) -+ xt_xlate_add(xl, "0x%02x", tos >> 2); -+ else if (!tos) -+ xt_xlate_add(xl, "%s dscp and 0x%02x", -+ ip, (uint8_t)~tosmask >> 2); -+ else if (tos == tosmask) -+ xt_xlate_add(xl, "%s dscp or 0x%02x", ip, tos >> 2); -+ else if (!tosmask) -+ xt_xlate_add(xl, "%s dscp xor 0x%02x", ip, tos >> 2); -+ else -+ xt_xlate_add(xl, "%s dscp and 0x%02x xor 0x%02x", -+ ip, (uint8_t)~tosmask >> 2, tos >> 2); -+ return 1; -+} -+ - static int tos_xlate(struct xt_xlate *xl, - const struct xt_xlate_tg_params *params) - { - const struct ipt_tos_target_info *info = - (struct ipt_tos_target_info *) params->target->data; -- uint8_t dscp = info->tos >> 2; -- -- xt_xlate_add(xl, "ip dscp set 0x%02x", dscp); - -- return 1; -+ return __tos_xlate(xl, "ip", info->tos, UINT8_MAX); - } - - static int tos_xlate6(struct xt_xlate *xl, - const struct xt_xlate_tg_params *params) - { -- const struct ipt_tos_target_info *info = -- (struct ipt_tos_target_info *) params->target->data; -- uint8_t dscp = info->tos >> 2; -+ const struct xt_tos_target_info *info = -+ (struct xt_tos_target_info *)params->target->data; - -- xt_xlate_add(xl, "ip6 dscp set 0x%02x", dscp); -- -- return 1; -+ return __tos_xlate(xl, "ip6", info->tos_value, info->tos_mask); - } - - static struct xtables_target tos_tg_reg[] = { -diff --git a/extensions/libxt_TOS.txlate b/extensions/libxt_TOS.txlate -index 0952310edc4ac..9c12674299359 100644 ---- a/extensions/libxt_TOS.txlate -+++ b/extensions/libxt_TOS.txlate -@@ -14,10 +14,13 @@ ip6tables-translate -A INPUT -j TOS --set-tos Normal-Service - nft add rule ip6 filter INPUT counter ip6 dscp set 0x00 - - ip6tables-translate -A INPUT -j TOS --and-tos 0x12 --nft add rule ip6 filter INPUT counter ip6 dscp set 0x00 -+nft add rule ip6 filter INPUT counter ip6 dscp set ip6 dscp and 0x04 - - ip6tables-translate -A INPUT -j TOS --or-tos 0x12 --nft add rule ip6 filter INPUT counter ip6 dscp set 0x04 -+nft add rule ip6 filter INPUT counter ip6 dscp set ip6 dscp or 0x04 - - ip6tables-translate -A INPUT -j TOS --xor-tos 0x12 --nft add rule ip6 filter INPUT counter ip6 dscp set 0x04 -+nft add rule ip6 filter INPUT counter ip6 dscp set ip6 dscp xor 0x04 -+ -+ip6tables-translate -A INPUT -j TOS --set-tos 0x12/0x34 -+nft add rule ip6 filter INPUT counter ip6 dscp set ip6 dscp and 0x32 xor 0x04 --- -2.38.0 - diff --git a/0031-extensions-ecn-Sanitize-xlate-callback.patch b/0031-extensions-ecn-Sanitize-xlate-callback.patch deleted file mode 100644 index 61b0a92..0000000 --- a/0031-extensions-ecn-Sanitize-xlate-callback.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 8ea7c325d2aaf6e1f0a13956c794deff3a7db860 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 17 Nov 2022 16:37:02 +0100 -Subject: [PATCH] extensions: ecn: Sanitize xlate callback - -Catch unexpected values in einfo->ip_ect. - -Fixes: ca42442093d3d ("iptables: extensions: libxt_ecn: Add translation to nft") -Signed-off-by: Phil Sutter -(cherry picked from commit 424ef98918d31377a305cdf1626e1c1f69ab6df1) ---- - extensions/libxt_ecn.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/extensions/libxt_ecn.c b/extensions/libxt_ecn.c -index ad3c7a0307a0d..83a4acfab7da7 100644 ---- a/extensions/libxt_ecn.c -+++ b/extensions/libxt_ecn.c -@@ -156,6 +156,8 @@ static int ecn_xlate(struct xt_xlate *xl, - case 3: - xt_xlate_add(xl, "ce"); - break; -+ default: -+ return 0; - } - } - return 1; --- -2.38.0 - diff --git a/0032-extensions-libxt_conntrack-Drop-extra-whitespace-in-.patch b/0032-extensions-libxt_conntrack-Drop-extra-whitespace-in-.patch deleted file mode 100644 index 9747eb2..0000000 --- a/0032-extensions-libxt_conntrack-Drop-extra-whitespace-in-.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 81f878657864668b48dc1aac951e0a90e74bc376 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 04:35:35 +0100 -Subject: [PATCH] extensions: libxt_conntrack: Drop extra whitespace in xlate - -No point in having this. Interestingly, other test cases even made up -for it. - -Fixes: 0afd957f6bc03 ("extensions: libxt_state: add translation to nft") -Signed-off-by: Phil Sutter -(cherry picked from commit 116848ea1e5d8d02fd766356a642bd81574e2723) - -Conflicts: - extensions/libxt_hashlimit.txlate ---- - extensions/libxt_SYNPROXY.txlate | 2 +- - extensions/libxt_conntrack.c | 1 - - extensions/libxt_hashlimit.txlate | 4 ++-- - 3 files changed, 3 insertions(+), 4 deletions(-) - -diff --git a/extensions/libxt_SYNPROXY.txlate b/extensions/libxt_SYNPROXY.txlate -index b3de2b2a8c9dc..a2a3b6c522fe7 100644 ---- a/extensions/libxt_SYNPROXY.txlate -+++ b/extensions/libxt_SYNPROXY.txlate -@@ -1,2 +1,2 @@ - iptables-translate -t mangle -A INPUT -i iifname -p tcp -m tcp --dport 80 -m state --state INVALID,UNTRACKED -j SYNPROXY --sack-perm --timestamp --wscale 7 --mss 1460 --nft add rule ip mangle INPUT iifname "iifname" tcp dport 80 ct state invalid,untracked counter synproxy sack-perm timestamp wscale 7 mss 1460 -+nft add rule ip mangle INPUT iifname "iifname" tcp dport 80 ct state invalid,untracked counter synproxy sack-perm timestamp wscale 7 mss 1460 -diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c -index 64018ce152b7a..614815a88c776 100644 ---- a/extensions/libxt_conntrack.c -+++ b/extensions/libxt_conntrack.c -@@ -1186,7 +1186,6 @@ static int state_xlate(struct xt_xlate *xl, - xt_xlate_add(xl, "ct state "); - state_xlate_print(xl, sinfo->state_mask, - sinfo->invert_flags & XT_CONNTRACK_STATE); -- xt_xlate_add(xl, " "); - return 1; - } - -diff --git a/extensions/libxt_hashlimit.txlate b/extensions/libxt_hashlimit.txlate -index 6c8d07f113d26..2fb6969befb4b 100644 ---- a/extensions/libxt_hashlimit.txlate -+++ b/extensions/libxt_hashlimit.txlate -@@ -1,5 +1,5 @@ - iptables-translate -A OUTPUT -m tcp -p tcp --dport 443 -m hashlimit --hashlimit-above 20kb/s --hashlimit-burst 1mb --hashlimit-mode dstip --hashlimit-name https --hashlimit-dstmask 24 -m state --state NEW -j DROP --nft add rule ip filter OUTPUT tcp dport 443 meter https { ip daddr and 255.255.255.0 timeout 60s limit rate over 20 kbytes/second burst 1 mbytes} ct state new counter drop -+nft add rule ip filter OUTPUT tcp dport 443 meter https { ip daddr and 255.255.255.0 timeout 60s limit rate over 20 kbytes/second burst 1 mbytes} ct state new counter drop - - iptables-translate -A OUTPUT -m tcp -p tcp --dport 443 -m hashlimit --hashlimit-upto 300 --hashlimit-burst 15 --hashlimit-mode srcip,dstip --hashlimit-name https --hashlimit-htable-expire 300000 -m state --state NEW -j DROP --nft add rule ip filter OUTPUT tcp dport 443 meter https { ip daddr . ip saddr timeout 300s limit rate 300/second burst 15 packets} ct state new counter drop -+nft add rule ip filter OUTPUT tcp dport 443 meter https { ip daddr . ip saddr timeout 300s limit rate 300/second burst 15 packets} ct state new counter drop --- -2.38.0 - diff --git a/0033-iptables-restore-Free-handle-with-test-also.patch b/0033-iptables-restore-Free-handle-with-test-also.patch deleted file mode 100644 index 922de98..0000000 --- a/0033-iptables-restore-Free-handle-with-test-also.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 1dd8538989bf60ba811d31f218d0bb7feb98e9b2 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 19:24:38 +0100 -Subject: [PATCH] iptables-restore: Free handle with --test also - -When running 'iptables-restore -t', valgrind reports: - -1,496 (160 direct, 1,336 indirect) bytes in 1 blocks are definitely lost in loss record 4 of 4 - at 0x48417E5: malloc (vg_replace_malloc.c:381) - by 0x4857A46: alloc_handle (libiptc.c:1279) - by 0x4857A46: iptc_init (libiptc.c:1342) - by 0x1167CE: create_handle (iptables-restore.c:72) - by 0x1167CE: ip46tables_restore_main (iptables-restore.c:229) - by 0x116DAE: iptables_restore_main (iptables-restore.c:388) - by 0x49A2349: (below main) (in /lib64/libc.so.6) - -Free the handle pointer before parsing the next table. - -Fixes: 1c9015b2cb483 ("libiptc: remove indirections") -Signed-off-by: Phil Sutter -(cherry picked from commit 18880dbde615449d00a3e38f3713a19d4566258e) ---- - iptables/iptables-restore.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/iptables/iptables-restore.c b/iptables/iptables-restore.c -index 4410a587597ba..c1c32f703afec 100644 ---- a/iptables/iptables-restore.c -+++ b/iptables/iptables-restore.c -@@ -184,12 +184,12 @@ ip46tables_restore_main(const struct iptables_restore_cb *cb, - if (!testing) { - DEBUGP("Calling commit\n"); - ret = cb->ops->commit(handle); -- cb->ops->free(handle); -- handle = NULL; - } else { - DEBUGP("Not calling commit, testing\n"); - ret = 1; - } -+ cb->ops->free(handle); -+ handle = NULL; - - /* Done with the current table, release the lock. */ - if (lock >= 0) { --- -2.38.0 - diff --git a/0034-iptables-xml-Free-allocated-chain-strings.patch b/0034-iptables-xml-Free-allocated-chain-strings.patch deleted file mode 100644 index 0289f2e..0000000 --- a/0034-iptables-xml-Free-allocated-chain-strings.patch +++ /dev/null @@ -1,42 +0,0 @@ -From ec615224255c3e36b6f423b711ca28ea5bcf5600 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 19:30:09 +0100 -Subject: [PATCH] iptables-xml: Free allocated chain strings - -Freeing only if 'created' is non-zero is wrong - the data was still -allocated. In fact, the field is supposed to prevent only the call to -openChain(). - -Fixes: 8d3eccb19a9c6 ("Add iptables-xml tool (Amin Azez )") -Signed-off-by: Phil Sutter -(cherry picked from commit 73da7fb74c1089391dac0aca70e13e5f5999ace7) ---- - iptables/iptables-xml.c | 10 +++++----- - 1 file changed, 5 insertions(+), 5 deletions(-) - -diff --git a/iptables/iptables-xml.c b/iptables/iptables-xml.c -index 6cf059fb67292..f168ddde48f06 100644 ---- a/iptables/iptables-xml.c -+++ b/iptables/iptables-xml.c -@@ -225,13 +225,13 @@ finishChains(void) - { - int c; - -- for (c = 0; c < nextChain; c++) -- if (!chains[c].created) { -+ for (c = 0; c < nextChain; c++) { -+ if (!chains[c].created) - openChain(chains[c].chain, chains[c].policy, - &(chains[c].count), '/'); -- free(chains[c].chain); -- free(chains[c].policy); -- } -+ free(chains[c].chain); -+ free(chains[c].policy); -+ } - nextChain = 0; - } - --- -2.38.0 - diff --git a/0035-nft-Plug-memleak-in-nft_rule_zero_counters.patch b/0035-nft-Plug-memleak-in-nft_rule_zero_counters.patch deleted file mode 100644 index 433f32b..0000000 --- a/0035-nft-Plug-memleak-in-nft_rule_zero_counters.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 5b58537268cd34eee4b31b445ea8fcf7d759e98f Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 21:21:22 +0100 -Subject: [PATCH] nft: Plug memleak in nft_rule_zero_counters() - -When zeroing a specific rule, valgrind reports: - -40 bytes in 1 blocks are definitely lost in loss record 1 of 1 - at 0x484659F: calloc (vg_replace_malloc.c:1328) - by 0x48DE128: xtables_calloc (xtables.c:434) - by 0x11C7C6: nft_parse_immediate (nft-shared.c:1071) - by 0x11C7C6: nft_rule_to_iptables_command_state (nft-shared.c:1236) - by 0x119AF5: nft_rule_zero_counters (nft.c:2877) - by 0x11A3CA: nft_prepare (nft.c:3445) - by 0x11A7A8: nft_commit (nft.c:3479) - by 0x114258: xtables_main.isra.0 (xtables-standalone.c:94) - by 0x1142D9: xtables_ip6_main (xtables-standalone.c:118) - by 0x49F2349: (below main) (in /lib64/libc.so.6) - -Have to free the matches/target in populated iptables_command_state object -again. While being at it, call the proper family_ops callbacks since this is -family-agnostic code. - -Fixes: a69cc575295ee ("xtables: allow to reset the counters of an existing rule") -Signed-off-by: Phil Sutter -(cherry picked from commit aa0c54030300441e9fd66c7016d0090f6736d449) ---- - iptables/nft.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/iptables/nft.c b/iptables/nft.c -index ee003511ab7f3..f836512fa0c22 100644 ---- a/iptables/nft.c -+++ b/iptables/nft.c -@@ -2862,10 +2862,11 @@ int nft_rule_zero_counters(struct nft_handle *h, const char *chain, - goto error; - } - -- nft_rule_to_iptables_command_state(h, r, &cs); -- -+ h->ops->rule_to_cs(h, r, &cs); - cs.counters.pcnt = cs.counters.bcnt = 0; - new_rule = nft_rule_new(h, chain, table, &cs); -+ h->ops->clear_cs(&cs); -+ - if (!new_rule) - return 1; - --- -2.38.0 - diff --git a/0036-xtables-Introduce-xtables_clear_iptables_command_sta.patch b/0036-xtables-Introduce-xtables_clear_iptables_command_sta.patch deleted file mode 100644 index dc8fb05..0000000 --- a/0036-xtables-Introduce-xtables_clear_iptables_command_sta.patch +++ /dev/null @@ -1,198 +0,0 @@ -From e3b810cd6f7a38cb0629a7e92b9e5263300f5bd9 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 21:42:20 +0100 -Subject: [PATCH] xtables: Introduce xtables_clear_iptables_command_state() - -This is nft_clear_iptables_command_state() but in a location reachable -by legacy iptables, too. - -Changes callers in non-family-specific code to use clear_cs callback -instead of directly calling it - ebtables still has a custom variant. - -Signed-off-by: Phil Sutter -(cherry picked from commit 365647ef056828bc3cb56efef12114951fcb730d) ---- - iptables/nft-arp.c | 4 ++-- - iptables/nft-ipv4.c | 4 ++-- - iptables/nft-ipv6.c | 4 ++-- - iptables/nft-shared.c | 14 -------------- - iptables/nft-shared.h | 1 - - iptables/xshared.c | 17 +++++++++++++++++ - iptables/xshared.h | 2 ++ - iptables/xtables-translate.c | 2 +- - iptables/xtables.c | 2 +- - 9 files changed, 27 insertions(+), 23 deletions(-) - -diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c -index e6e4d2d81e528..af19510e58013 100644 ---- a/iptables/nft-arp.c -+++ b/iptables/nft-arp.c -@@ -490,7 +490,7 @@ nft_arp_print_rule(struct nft_handle *h, struct nftnl_rule *r, - if (!(format & FMT_NONEWLINE)) - fputc('\n', stdout); - -- nft_clear_iptables_command_state(&cs); -+ xtables_clear_iptables_command_state(&cs); - } - - static bool nft_arp_is_same(const struct iptables_command_state *cs_a, -@@ -787,7 +787,7 @@ struct nft_family_ops nft_family_ops_arp = { - }, - .rule_to_cs = nft_rule_to_iptables_command_state, - .init_cs = nft_arp_init_cs, -- .clear_cs = nft_clear_iptables_command_state, -+ .clear_cs = xtables_clear_iptables_command_state, - .parse_target = nft_ipv46_parse_target, - .add_entry = nft_arp_add_entry, - .delete_entry = nft_arp_delete_entry, -diff --git a/iptables/nft-ipv4.c b/iptables/nft-ipv4.c -index 59c4a41f1a05f..5793ba878dbda 100644 ---- a/iptables/nft-ipv4.c -+++ b/iptables/nft-ipv4.c -@@ -244,7 +244,7 @@ static void nft_ipv4_print_rule(struct nft_handle *h, struct nftnl_rule *r, - if (!(format & FMT_NONEWLINE)) - fputc('\n', stdout); - -- nft_clear_iptables_command_state(&cs); -+ xtables_clear_iptables_command_state(&cs); - } - - static void nft_ipv4_save_rule(const struct iptables_command_state *cs, -@@ -451,7 +451,7 @@ struct nft_family_ops nft_family_ops_ipv4 = { - }, - .parse_target = nft_ipv46_parse_target, - .rule_to_cs = nft_rule_to_iptables_command_state, -- .clear_cs = nft_clear_iptables_command_state, -+ .clear_cs = xtables_clear_iptables_command_state, - .xlate = nft_ipv4_xlate, - .add_entry = nft_ipv4_add_entry, - .delete_entry = nft_ipv4_delete_entry, -diff --git a/iptables/nft-ipv6.c b/iptables/nft-ipv6.c -index 9a29d18bc215c..1457b0411b8a6 100644 ---- a/iptables/nft-ipv6.c -+++ b/iptables/nft-ipv6.c -@@ -205,7 +205,7 @@ static void nft_ipv6_print_rule(struct nft_handle *h, struct nftnl_rule *r, - if (!(format & FMT_NONEWLINE)) - fputc('\n', stdout); - -- nft_clear_iptables_command_state(&cs); -+ xtables_clear_iptables_command_state(&cs); - } - - static void nft_ipv6_save_rule(const struct iptables_command_state *cs, -@@ -417,7 +417,7 @@ struct nft_family_ops nft_family_ops_ipv6 = { - }, - .parse_target = nft_ipv46_parse_target, - .rule_to_cs = nft_rule_to_iptables_command_state, -- .clear_cs = nft_clear_iptables_command_state, -+ .clear_cs = xtables_clear_iptables_command_state, - .xlate = nft_ipv6_xlate, - .add_entry = nft_ipv6_add_entry, - .delete_entry = nft_ipv6_delete_entry, -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 74e19ccad226d..98712be9c0136 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -1227,20 +1227,6 @@ void nft_rule_to_iptables_command_state(struct nft_handle *h, - cs->jumpto = ""; - } - --void nft_clear_iptables_command_state(struct iptables_command_state *cs) --{ -- xtables_rule_matches_free(&cs->matches); -- if (cs->target) { -- free(cs->target->t); -- cs->target->t = NULL; -- -- if (cs->target == cs->target->next) { -- free(cs->target); -- cs->target = NULL; -- } -- } --} -- - void nft_ipv46_save_chain(const struct nftnl_chain *c, const char *policy) - { - const char *chain = nftnl_chain_get_str(c, NFTNL_CHAIN_NAME); -diff --git a/iptables/nft-shared.h b/iptables/nft-shared.h -index b040490471167..07a2680d7a286 100644 ---- a/iptables/nft-shared.h -+++ b/iptables/nft-shared.h -@@ -163,7 +163,6 @@ void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv); - void nft_rule_to_iptables_command_state(struct nft_handle *h, - const struct nftnl_rule *r, - struct iptables_command_state *cs); --void nft_clear_iptables_command_state(struct iptables_command_state *cs); - void print_matches_and_target(struct iptables_command_state *cs, - unsigned int format); - void nft_ipv46_save_chain(const struct nftnl_chain *c, const char *policy); -diff --git a/iptables/xshared.c b/iptables/xshared.c -index a8512d3808154..7711af532f0a6 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -1354,6 +1354,23 @@ static const char *optstring_lookup(int family) - return ""; - } - -+void xtables_clear_iptables_command_state(struct iptables_command_state *cs) -+{ -+ xtables_rule_matches_free(&cs->matches); -+ if (cs->target) { -+ free(cs->target->t); -+ cs->target->t = NULL; -+ -+ free(cs->target->udata); -+ cs->target->udata = NULL; -+ -+ if (cs->target == cs->target->next) { -+ free(cs->target); -+ cs->target = NULL; -+ } -+ } -+} -+ - void do_parse(int argc, char *argv[], - struct xt_cmd_parse *p, struct iptables_command_state *cs, - struct xtables_args *args) -diff --git a/iptables/xshared.h b/iptables/xshared.h -index e45ab660c03fb..929ebe63a033c 100644 ---- a/iptables/xshared.h -+++ b/iptables/xshared.h -@@ -158,6 +158,8 @@ struct iptables_command_state { - bool restore; - }; - -+void xtables_clear_iptables_command_state(struct iptables_command_state *cs); -+ - typedef int (*mainfunc_t)(int, char **); - - struct subcommand { -diff --git a/iptables/xtables-translate.c b/iptables/xtables-translate.c -index d1e87f167df74..e3fe5eaedf621 100644 ---- a/iptables/xtables-translate.c -+++ b/iptables/xtables-translate.c -@@ -341,7 +341,7 @@ static int do_command_xlate(struct nft_handle *h, int argc, char *argv[], - exit(1); - } - -- nft_clear_iptables_command_state(&cs); -+ h->ops->clear_cs(&cs); - - if (h->family == AF_INET) { - free(args.s.addr.v4); -diff --git a/iptables/xtables.c b/iptables/xtables.c -index 70924176df8c1..22d6ea58376fc 100644 ---- a/iptables/xtables.c -+++ b/iptables/xtables.c -@@ -262,7 +262,7 @@ int do_commandx(struct nft_handle *h, int argc, char *argv[], char **table, - - *table = p.table; - -- nft_clear_iptables_command_state(&cs); -+ h->ops->clear_cs(&cs); - - free(args.s.addr.ptr); - free(args.s.mask.ptr); --- -2.38.0 - diff --git a/0037-iptables-Properly-clear-iptables_command_state-objec.patch b/0037-iptables-Properly-clear-iptables_command_state-objec.patch deleted file mode 100644 index 907aafd..0000000 --- a/0037-iptables-Properly-clear-iptables_command_state-objec.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 30e973049cfe000289b3f25c85d27e7cbc24f299 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 25 Nov 2022 21:44:39 +0100 -Subject: [PATCH] iptables: Properly clear iptables_command_state object - -When adding a rule with a target which defines a udata_size, valgrind -prints: - -8 bytes in 1 blocks are definitely lost in loss record 1 of 1 - at 0x484659F: calloc (vg_replace_malloc.c:1328) - by 0x486B128: xtables_calloc (xtables.c:434) - by 0x1128B4: xs_init_target (xshared.c:238) - by 0x113CD3: command_jump (xshared.c:877) - by 0x114969: do_parse (xshared.c:1644) - by 0x10EEB9: do_command4 (iptables.c:691) - by 0x10E45B: iptables_main (iptables-standalone.c:59) - by 0x49A2349: (below main) (in /lib64/libc.so.6) - -It is not sufficient to free cs.target->t, so call -xtables_clear_iptables_command_state() which takes care of all the -details. - -Fixes: 2dba676b68ef8 ("extensions: support for per-extension instance "global" variable space") -Signed-off-by: Phil Sutter -(cherry picked from commit 8bee0db39f7553589c2cec58cc92ed2eafd2eb57) ---- - iptables/ip6tables.c | 3 +-- - iptables/iptables.c | 3 +-- - 2 files changed, 2 insertions(+), 4 deletions(-) - -diff --git a/iptables/ip6tables.c b/iptables/ip6tables.c -index 75984cc1bcdd8..6989dc7a91a73 100644 ---- a/iptables/ip6tables.c -+++ b/iptables/ip6tables.c -@@ -806,7 +806,6 @@ int do_command6(int argc, char *argv[], char **table, - xtables_find_target(cs.jumpto, XTF_LOAD_MUST_SUCCEED); - } else { - e = generate_entry(&cs.fw6, cs.matches, cs.target->t); -- free(cs.target->t); - } - } - -@@ -908,7 +907,7 @@ int do_command6(int argc, char *argv[], char **table, - if (verbose > 1) - dump_entries6(*handle); - -- xtables_rule_matches_free(&cs.matches); -+ xtables_clear_iptables_command_state(&cs); - - if (e != NULL) { - free(e); -diff --git a/iptables/iptables.c b/iptables/iptables.c -index e5207ba106057..44274c7b3e900 100644 ---- a/iptables/iptables.c -+++ b/iptables/iptables.c -@@ -801,7 +801,6 @@ int do_command4(int argc, char *argv[], char **table, - xtables_find_target(cs.jumpto, XTF_LOAD_MUST_SUCCEED); - } else { - e = generate_entry(&cs.fw, cs.matches, cs.target->t); -- free(cs.target->t); - } - } - -@@ -903,7 +902,7 @@ int do_command4(int argc, char *argv[], char **table, - if (verbose > 1) - dump_entries(*handle); - -- xtables_rule_matches_free(&cs.matches); -+ xtables_clear_iptables_command_state(&cs); - - if (e != NULL) { - free(e); --- -2.38.0 - diff --git a/0038-libiptc-Eliminate-garbage-access.patch b/0038-libiptc-Eliminate-garbage-access.patch deleted file mode 100644 index f6a065f..0000000 --- a/0038-libiptc-Eliminate-garbage-access.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 9e7d35cee9f00fae748ef0b3cf391d29305b715c Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 30 Nov 2022 20:03:30 +0100 -Subject: [PATCH] libiptc: Eliminate garbage access - -When adding a rule, valgrind prints: - -Syscall param socketcall.setsockopt(optval) points to uninitialised byte(s) - at 0x4A8165A: setsockopt (in /lib64/libc.so.6) - by 0x4857A48: iptc_commit (libiptc.c:2676) - by 0x10E4BB: iptables_main (iptables-standalone.c:61) - by 0x49A3349: (below main) (in /lib64/libc.so.6) - Address 0x4b63788 is 40 bytes inside a block of size 1,448 alloc'd - at 0x484659F: calloc (vg_replace_malloc.c:1328) - by 0x4857654: iptc_commit (libiptc.c:2564) - by 0x10E4BB: iptables_main (iptables-standalone.c:61) - by 0x49A3349: (below main) (in /lib64/libc.so.6) - -This is because repl->counters is not initialized upon allocation. Since -the field is an array, make use of calloc() which implicitly does the -initialization. - -Fixes: e37c0dc100c51 ("Revert the recent addition of memset()'s to TC_COMMIT. One of them is bogus and the other one needs more investigation to why valgrind is complaining.") -Signed-off-by: Phil Sutter -(cherry picked from commit 39a2aa8cbfc99f4a75dfc0786a80ced90952ab29) ---- - libiptc/libiptc.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/libiptc/libiptc.c b/libiptc/libiptc.c -index 97823f935d1ee..f9b7779efdba5 100644 ---- a/libiptc/libiptc.c -+++ b/libiptc/libiptc.c -@@ -2554,8 +2554,8 @@ TC_COMMIT(struct xtc_handle *handle) - + sizeof(STRUCT_COUNTERS) * new_number; - - /* These are the old counters we will get from kernel */ -- repl->counters = malloc(sizeof(STRUCT_COUNTERS) -- * handle->info.num_entries); -+ repl->counters = calloc(handle->info.num_entries, -+ sizeof(STRUCT_COUNTERS)); - if (!repl->counters) { - errno = ENOMEM; - goto out_free_repl; --- -2.38.0 - diff --git a/0039-nft-Fix-for-comparing-ifname-matches-against-nft-gen.patch b/0039-nft-Fix-for-comparing-ifname-matches-against-nft-gen.patch deleted file mode 100644 index 27d0235..0000000 --- a/0039-nft-Fix-for-comparing-ifname-matches-against-nft-gen.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 70dfd24723cb2ed263dbc6c69b2293885d3d6879 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 1 Dec 2022 13:09:48 +0100 -Subject: [PATCH] nft: Fix for comparing ifname matches against nft-generated - ones - -Since nft adds the interface name as fixed-size string of 16 bytes, -filling a mask based on the length value will not match the mask nft -set. - -Fixes: 652b98e793711 ("xtables-compat: fix wildcard detection") -Signed-off-by: Phil Sutter -(cherry picked from commit f200aca7ff7b6a0edbe9024f0543b3f58111c50e) ---- - iptables/nft-shared.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 98712be9c0136..0be79f2a8b76e 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -275,7 +275,7 @@ static void parse_ifname(const char *name, unsigned int len, char *dst, unsigned - memcpy(dst, name, len); - if (name[len - 1] == '\0') { - if (mask) -- memset(mask, 0xff, len); -+ memset(mask, 0xff, strlen(name) + 1); - return; - } - --- -2.38.0 - diff --git a/0040-nft-Fix-match-generator-for-i.patch b/0040-nft-Fix-match-generator-for-i.patch deleted file mode 100644 index 46f5019..0000000 --- a/0040-nft-Fix-match-generator-for-i.patch +++ /dev/null @@ -1,47 +0,0 @@ -From da96a3c088d413db6e442fdd0a0d85d15a65e906 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 1 Dec 2022 15:08:01 +0100 -Subject: [PATCH] nft: Fix match generator for '! -i +' - -It's actually nonsense since it will never match, but iptables accepts -it and the resulting nftables rule must behave identically. Reuse the -solution implemented into xtables-translate (by commit e179e87a1179e) -and turn the above match into 'iifname INVAL/D'. - -The commit this fixes merely ignored the fact that "any interface" match -might be inverted. - -Fixes: 0a8635183edd0 ("xtables-compat: ignore '+' interface name") -Signed-off-by: Phil Sutter -(cherry picked from commit 5baa4279264bb4ab93c6e80b4887f2bd29691446) ---- - iptables/nft-shared.c | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 0be79f2a8b76e..17c4489b508ba 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -164,6 +164,9 @@ void add_iniface(struct nft_handle *h, struct nftnl_rule *r, - if (iface[iface_len - 1] == '+') { - if (iface_len > 1) - add_cmp_ptr(r, op, iface, iface_len - 1, reg); -+ else if (op != NFT_CMP_EQ) -+ add_cmp_ptr(r, NFT_CMP_EQ, "INVAL/D", -+ strlen("INVAL/D") + 1, reg); - } else { - add_cmp_ptr(r, op, iface, iface_len + 1, reg); - } -@@ -181,6 +184,9 @@ void add_outiface(struct nft_handle *h, struct nftnl_rule *r, - if (iface[iface_len - 1] == '+') { - if (iface_len > 1) - add_cmp_ptr(r, op, iface, iface_len - 1, reg); -+ else if (op != NFT_CMP_EQ) -+ add_cmp_ptr(r, NFT_CMP_EQ, "INVAL/D", -+ strlen("INVAL/D") + 1, reg); - } else { - add_cmp_ptr(r, op, iface, iface_len + 1, reg); - } --- -2.38.0 - diff --git a/0041-xtables-translate-Fix-for-interfaces-with-asterisk-m.patch b/0041-xtables-translate-Fix-for-interfaces-with-asterisk-m.patch deleted file mode 100644 index a19b8a0..0000000 --- a/0041-xtables-translate-Fix-for-interfaces-with-asterisk-m.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 4494d0b91705d7144782eb8106735b699eb30494 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 1 Dec 2022 15:16:43 +0100 -Subject: [PATCH] xtables-translate: Fix for interfaces with asterisk - mid-string - -For nft, asterisk is special at end of the interface name only. Escaping -it mid-string makes the escape char part of the interface name, so avoid -this. - -In the test case, also drop the ticks around interface names in -*-translate command - since there's no shell involved which would eat -them, they become part of the interface name. - -Fixes: e179e87a1179e ("xtables-translate: Fix for interface name corner-cases") -Signed-off-by: Phil Sutter -(cherry picked from commit ba1c0fe89eb56f8bf25f9165f2e5dc366ea0118c) - -Conflicts: - extensions/generic.txlate ---- - extensions/generic.txlate | 4 ++-- - iptables/xtables-translate.c | 4 +++- - 2 files changed, 5 insertions(+), 3 deletions(-) - -diff --git a/extensions/generic.txlate b/extensions/generic.txlate -index 9ae9a5b54c1b9..1e160c4b66dc0 100644 ---- a/extensions/generic.txlate -+++ b/extensions/generic.txlate -@@ -69,11 +69,11 @@ nft insert rule bridge filter INPUT ether type 0x800 ether daddr 01:02:03:04:00: - - # asterisk is not special in iptables and it is even a valid interface name - iptables-translate -A FORWARD -i '*' -o 'eth*foo' --nft add rule ip filter FORWARD iifname "\*" oifname "eth\*foo" counter -+nft add rule ip filter FORWARD iifname "\*" oifname "eth*foo" counter - - # escape all asterisks but translate only the first plus character - iptables-translate -A FORWARD -i 'eth*foo*+' -o 'eth++' --nft add rule ip filter FORWARD iifname "eth\*foo\**" oifname "eth+*" counter -+nft add rule ip filter FORWARD iifname "eth*foo**" oifname "eth+*" counter - - # skip for always matching interface names - iptables-translate -A FORWARD -i '+' -diff --git a/iptables/xtables-translate.c b/iptables/xtables-translate.c -index e3fe5eaedf621..11812ed85f96b 100644 ---- a/iptables/xtables-translate.c -+++ b/iptables/xtables-translate.c -@@ -41,7 +41,9 @@ void xlate_ifname(struct xt_xlate *xl, const char *nftmeta, const char *ifname, - for (i = 0, j = 0; i < ifaclen + 1; i++, j++) { - switch (ifname[i]) { - case '*': -- iface[j++] = '\\'; -+ /* asterisk is non-special mid-string */ -+ if (i == ifaclen - 1) -+ iface[j++] = '\\'; - /* fall through */ - default: - iface[j] = ifname[i]; --- -2.38.0 - diff --git a/0042-ebtables-Fix-MAC-address-match-translation.patch b/0042-ebtables-Fix-MAC-address-match-translation.patch deleted file mode 100644 index 5b7e1fc..0000000 --- a/0042-ebtables-Fix-MAC-address-match-translation.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 40908185929a13ff4a0d36c713ea630989d906f0 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 1 Dec 2022 13:03:49 +0100 -Subject: [PATCH] ebtables: Fix MAC address match translation - -If a mask was present, ebtables-translate would emit illegal syntax. - -Fixes: 5e2b473a64bc7 ("xtables-compat: extend generic tests for masks and wildcards") -Signed-off-by: Phil Sutter -(cherry picked from commit 39589b3edb7c0ea3e64777c7f4cdbf45be55ce53) - -Conflicts: - extensions/generic.txlate - Also fixed for missing xlate auto-spacing ---- - extensions/generic.txlate | 2 +- - iptables/nft-bridge.c | 6 +++--- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/extensions/generic.txlate b/extensions/generic.txlate -index 1e160c4b66dc0..7afac03f36c86 100644 ---- a/extensions/generic.txlate -+++ b/extensions/generic.txlate -@@ -65,7 +65,7 @@ ebtables-translate -A FORWARD ! -i iname --logical-in ilogname -o out+ --logical - nft add rule bridge filter FORWARD iifname != "iname" meta ibrname "ilogname" oifname "out*" meta obrname "lout*" ether daddr 01:02:03:04:de:af counter - - ebtables-translate -I INPUT -p ip -d 1:2:3:4:5:6/ff:ff:ff:ff:00:00 --nft insert rule bridge filter INPUT ether type 0x800 ether daddr 01:02:03:04:00:00 and ff:ff:ff:ff:00:00 == 01:02:03:04:00:00 counter -+nft insert rule bridge filter INPUT ether type 0x800 ether daddr and ff:ff:ff:ff:00:00 == 01:02:03:04:00:00 counter - - # asterisk is not special in iptables and it is even a valid interface name - iptables-translate -A FORWARD -i '*' -o 'eth*foo' -diff --git a/iptables/nft-bridge.c b/iptables/nft-bridge.c -index 106bcc72889f6..81b3aca3e6933 100644 ---- a/iptables/nft-bridge.c -+++ b/iptables/nft-bridge.c -@@ -810,17 +810,17 @@ static void nft_bridge_xlate_mac(struct xt_xlate *xl, const char *type, bool inv - - xt_xlate_add(xl, "ether %s %s", type, invert ? "!= " : ""); - -- xlate_mac(xl, mac); -- - if (memcmp(mask, one_msk, ETH_ALEN)) { - int i; -- xt_xlate_add(xl, " and "); -+ xt_xlate_add(xl, "and "); - - xlate_mac(xl, mask); - - xt_xlate_add(xl, " == %02x", mac[0] & mask[0]); - for (i=1; i < ETH_ALEN; i++) - xt_xlate_add(xl, ":%02x", mac[i] & mask[i]); -+ } else { -+ xlate_mac(xl, mac); - } - - xt_xlate_add(xl, " "); --- -2.38.0 - diff --git a/0043-Drop-libiptc-linux_stddef.h.patch b/0043-Drop-libiptc-linux_stddef.h.patch deleted file mode 100644 index ee57ebf..0000000 --- a/0043-Drop-libiptc-linux_stddef.h.patch +++ /dev/null @@ -1,63 +0,0 @@ -From 170fbbf33023edada831ab0827f5622b01abaf7d Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Sat, 3 Dec 2022 22:45:59 +0100 -Subject: [PATCH] Drop libiptc/linux_stddef.h - -This header was never included anywhere. - -Fixes: aae69bed01982 ("complete libiptc rewrite. Time to load 10k rules goes down from 2.20 minutes to 1.255 seconds (!). Might still contain bugs, use with caution.") -Signed-off-by: Phil Sutter -(cherry picked from commit 53153775b08f830b940d04efbc7b38bc40aaa4b3) ---- - libiptc/linux_stddef.h | 39 --------------------------------------- - 1 file changed, 39 deletions(-) - delete mode 100644 libiptc/linux_stddef.h - -diff --git a/libiptc/linux_stddef.h b/libiptc/linux_stddef.h -deleted file mode 100644 -index 56416f104ecfc..0000000000000 ---- a/libiptc/linux_stddef.h -+++ /dev/null -@@ -1,39 +0,0 @@ --#ifndef _LINUX_STDDEF_H --#define _LINUX_STDDEF_H -- --#undef NULL --#if defined(__cplusplus) --#define NULL 0 --#else --#define NULL ((void *)0) --#endif -- --#undef offsetof --#define offsetof(TYPE, MEMBER) ((size_t) &((TYPE *)0)->MEMBER) -- -- --/** -- * container_of - cast a member of a structure out to the containing structure -- * -- * @ptr: the pointer to the member. -- * @type: the type of the container struct this is embedded in. -- * @member: the name of the member within the struct. -- * -- */ --#define container_of(ptr, type, member) ({ \ -- const typeof( ((type *)0)->member ) *__mptr = (ptr); \ -- (type *)( (char *)__mptr - offsetof(type,member) );}) -- --/* -- * Check at compile time that something is of a particular type. -- * Always evaluates to 1 so you may use it easily in comparisons. -- */ --#define typecheck(type,x) \ --({ type __dummy; \ -- typeof(x) __dummy2; \ -- (void)(&__dummy == &__dummy2); \ -- 1; \ --}) -- -- --#endif --- -2.38.0 - diff --git a/0044-include-Makefile-xtables-version.h-is-generated.patch b/0044-include-Makefile-xtables-version.h-is-generated.patch deleted file mode 100644 index 74b56bd..0000000 --- a/0044-include-Makefile-xtables-version.h-is-generated.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 1175933cad01daea3c8f4fc8bfbbf951b8e221c6 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 7 Dec 2022 17:23:12 +0100 -Subject: [PATCH] include/Makefile: xtables-version.h is generated - -List it in nodist_include_HEADERS so it is installed but not -distributed - configure generates it from xtables-version.h.in. - -While being at it, list xtables.h in plain include_HEADERS. It doesn't -sit in a sub-dir, so the nobase prefix does not make a difference. - -Fixes: df60a301bf24c ("build: separate AC variable replacements from xtables.h") -Signed-off-by: Phil Sutter -(cherry picked from commit 19f03b7a2a21f22a53b6b0d2f542062986e2f807) ---- - include/Makefile.am | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/include/Makefile.am b/include/Makefile.am -index ea34c2fef0d98..25f8d0263574b 100644 ---- a/include/Makefile.am -+++ b/include/Makefile.am -@@ -1,13 +1,13 @@ - # -*- Makefile -*- - --include_HEADERS = --nobase_include_HEADERS = xtables.h xtables-version.h -+include_HEADERS = xtables.h -+nodist_include_HEADERS = xtables-version.h - - if ENABLE_LIBIPQ - include_HEADERS += libipq/libipq.h - endif - --nobase_include_HEADERS += \ -+nobase_include_HEADERS = \ - libiptc/ipt_kernel_headers.h libiptc/libiptc.h \ - libiptc/libip6tc.h libiptc/libxtc.h libiptc/xtcshared.h - --- -2.38.0 - diff --git a/0045-extensions-libxt_conntrack-remove-always-false-condi.patch b/0045-extensions-libxt_conntrack-remove-always-false-condi.patch deleted file mode 100644 index 30efdd2..0000000 --- a/0045-extensions-libxt_conntrack-remove-always-false-condi.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 40837fafb03f8ec9394b34a524d3e6cf22a26b22 Mon Sep 17 00:00:00 2001 -From: Florian Westphal -Date: Sat, 23 Jul 2022 20:25:49 +0200 -Subject: [PATCH] extensions: libxt_conntrack: remove always-false conditionals - -libxt_conntrack.c:1292: warning: the comparison will always evaluate as -false for the address of origsrc_addr will never be NULL [-Waddress] - -Signed-off-by: Florian Westphal -(cherry picked from commit e88085ac41b4c962e1d85dcc8dc6fa0d1f80dc12) ---- - extensions/libxt_conntrack.c | 12 ------------ - 1 file changed, 12 deletions(-) - -diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c -index 614815a88c776..0e7932e71fb85 100644 ---- a/extensions/libxt_conntrack.c -+++ b/extensions/libxt_conntrack.c -@@ -1288,9 +1288,6 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl, - } - - if (sinfo->match_flags & XT_CONNTRACK_ORIGSRC) { -- if (&sinfo->origsrc_addr == 0L) -- return 0; -- - xt_xlate_add(xl, "%sct original saddr %s", space, - sinfo->invert_flags & XT_CONNTRACK_ORIGSRC ? - "!= " : ""); -@@ -1300,9 +1297,6 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl, - } - - if (sinfo->match_flags & XT_CONNTRACK_ORIGDST) { -- if (&sinfo->origdst_addr == 0L) -- return 0; -- - xt_xlate_add(xl, "%sct original daddr %s", space, - sinfo->invert_flags & XT_CONNTRACK_ORIGDST ? - "!= " : ""); -@@ -1312,9 +1306,6 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl, - } - - if (sinfo->match_flags & XT_CONNTRACK_REPLSRC) { -- if (&sinfo->replsrc_addr == 0L) -- return 0; -- - xt_xlate_add(xl, "%sct reply saddr %s", space, - sinfo->invert_flags & XT_CONNTRACK_REPLSRC ? - "!= " : ""); -@@ -1324,9 +1315,6 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl, - } - - if (sinfo->match_flags & XT_CONNTRACK_REPLDST) { -- if (&sinfo->repldst_addr == 0L) -- return 0; -- - xt_xlate_add(xl, "%sct reply daddr %s", space, - sinfo->invert_flags & XT_CONNTRACK_REPLDST ? - "!= " : ""); --- -2.38.0 - diff --git a/0046-nft-Reject-tcp-udp-extension-without-proper-protocol.patch b/0046-nft-Reject-tcp-udp-extension-without-proper-protocol.patch deleted file mode 100644 index 1ae53d6..0000000 --- a/0046-nft-Reject-tcp-udp-extension-without-proper-protocol.patch +++ /dev/null @@ -1,71 +0,0 @@ -From bc0da367d74521aec0f577ae811d30f4db00f4ab Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 22 Dec 2022 15:58:27 +0100 -Subject: [PATCH] nft: Reject tcp/udp extension without proper protocol match - -Internally, 'th' expression is used, which works but matches both -protocols. Since users won't expect '-m tcp --dport 1' to match UDP -packets, catch missing/wrong '-p' argument. - -Fixes: c034cf31dd1a9 ("nft: prefer native expressions instead of udp match") -Signed-off-by: Phil Sutter -(cherry picked from commit 596f2e31ae7cee26e4f39f300cc69605f4ba512f) ---- - extensions/libxt_tcp.t | 3 +++ - extensions/libxt_udp.t | 3 +++ - iptables/nft.c | 6 ++++++ - 3 files changed, 12 insertions(+) - -diff --git a/extensions/libxt_tcp.t b/extensions/libxt_tcp.t -index b0e8006e51869..7a3bbd08952f0 100644 ---- a/extensions/libxt_tcp.t -+++ b/extensions/libxt_tcp.t -@@ -22,5 +22,8 @@ - -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG SYN;=;OK - -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,PSH,ACK,URG SYN;=;OK - -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG RST;=;OK -+-m tcp --dport 1;;FAIL -+-m tcp --dport 1 -p tcp;-p tcp -m tcp --dport 1;OK -+-m tcp --dport 1 -p 6;-p tcp -m tcp --dport 1;OK - # should we accept this below? - -p tcp -m tcp;=;OK -diff --git a/extensions/libxt_udp.t b/extensions/libxt_udp.t -index 1b4d3dd625759..f534770191a6e 100644 ---- a/extensions/libxt_udp.t -+++ b/extensions/libxt_udp.t -@@ -18,5 +18,8 @@ - # -p udp -m udp --sport 65536;;FAIL - -p udp -m udp --sport -1;;FAIL - -p udp -m udp --dport -1;;FAIL -+-m udp --dport 1;;FAIL -+-m udp --dport 1 -p udp;-p udp -m udp --dport 1;OK -+-m udp --dport 1 -p 17;-p udp -m udp --dport 1;OK - # should we accept this below? - -p udp -m udp;=;OK -diff --git a/iptables/nft.c b/iptables/nft.c -index f836512fa0c22..03f4d7b69cd4d 100644 ---- a/iptables/nft.c -+++ b/iptables/nft.c -@@ -1362,6 +1362,9 @@ static int add_nft_udp(struct nft_handle *h, struct nftnl_rule *r, - return ret; - } - -+ if (nftnl_rule_get_u32(r, NFTNL_RULE_COMPAT_PROTO) != IPPROTO_UDP) -+ xtables_error(PARAMETER_PROBLEM, "UDP match requires '-p udp'"); -+ - return add_nft_tcpudp(h, r, udp->spts, udp->invflags & XT_UDP_INV_SRCPT, - udp->dpts, udp->invflags & XT_UDP_INV_DSTPT); - } -@@ -1412,6 +1415,9 @@ static int add_nft_tcp(struct nft_handle *h, struct nftnl_rule *r, - return ret; - } - -+ if (nftnl_rule_get_u32(r, NFTNL_RULE_COMPAT_PROTO) != IPPROTO_TCP) -+ xtables_error(PARAMETER_PROBLEM, "TCP match requires '-p tcp'"); -+ - if (tcp->flg_mask) { - int ret = add_nft_tcpflags(h, r, tcp->flg_cmp, tcp->flg_mask, - tcp->invflags & XT_TCP_INV_FLAGS); --- -2.40.0 - diff --git a/0047-gitignore-Ignore-utils-nfsynproxy.patch b/0047-gitignore-Ignore-utils-nfsynproxy.patch deleted file mode 100644 index 3a9c6d8..0000000 --- a/0047-gitignore-Ignore-utils-nfsynproxy.patch +++ /dev/null @@ -1,24 +0,0 @@ -From fd627987ad51531c28296067623d5066a45ecabb Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Thu, 22 Dec 2022 17:23:49 +0100 -Subject: [PATCH] gitignore: Ignore utils/nfsynproxy - -Fixes: 9e6928f037823 ("utils: add nfsynproxy tool") -Signed-off-by: Phil Sutter -(cherry picked from commit 567f6ba105302f57ccb6789dbcfc9e1e2657809a) ---- - utils/.gitignore | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/utils/.gitignore b/utils/.gitignore -index 6300812b1701b..e508bb3270c4f 100644 ---- a/utils/.gitignore -+++ b/utils/.gitignore -@@ -2,3 +2,4 @@ - /nfnl_osf.8 - /nfbpf_compile - /nfbpf_compile.8 -+/nfsynproxy --- -2.40.0 - diff --git a/0048-etc-Drop-xtables.conf.patch b/0048-etc-Drop-xtables.conf.patch deleted file mode 100644 index 83eb99a..0000000 --- a/0048-etc-Drop-xtables.conf.patch +++ /dev/null @@ -1,118 +0,0 @@ -From b831e992189a58dbe5f7e95cffaed6b55501ad63 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 17 Jan 2023 16:38:43 +0100 -Subject: [PATCH] etc: Drop xtables.conf - -The file is not used since the commit this one fixes. Also it wasn't -installed until recently, when commit 3822a992bc277 ("Makefile: Fix for -'make distcheck'") added it in the wrong spot in an attempt to reduce -differences between tarballs generated by 'make tarball' and 'make -dist'. - -While being at it, drop stale xtables_config_main() prototype from -xtables-multi.h. - -Fixes: 06fd5e46d46f7 ("xtables: Drop support for /etc/xtables.conf") -Signed-off-by: Phil Sutter -(cherry picked from commit ca8fb6c21b298b3d96db2bfbf9c74d393bdd4728) ---- - etc/xtables.conf | 74 ---------------------------------------- - iptables/xtables-multi.h | 1 - - 2 files changed, 75 deletions(-) - delete mode 100644 etc/xtables.conf - -diff --git a/etc/xtables.conf b/etc/xtables.conf -deleted file mode 100644 -index 3c54ced043d82..0000000000000 ---- a/etc/xtables.conf -+++ /dev/null -@@ -1,74 +0,0 @@ --family ipv4 { -- table raw { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 -- } -- -- table mangle { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 -- chain INPUT hook NF_INET_LOCAL_IN prio -150 -- chain FORWARD hook NF_INET_FORWARD prio -150 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 -- chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 -- } -- -- table filter { -- chain INPUT hook NF_INET_LOCAL_IN prio 0 -- chain FORWARD hook NF_INET_FORWARD prio 0 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 -- } -- -- table nat { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 -- chain INPUT hook NF_INET_LOCAL_IN prio 100 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 -- chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 -- } -- -- table security { -- chain INPUT hook NF_INET_LOCAL_IN prio 50 -- chain FORWARD hook NF_INET_FORWARD prio 50 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 -- } --} -- --family ipv6 { -- table raw { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -300 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -300 -- } -- -- table mangle { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -150 -- chain INPUT hook NF_INET_LOCAL_IN prio -150 -- chain FORWARD hook NF_INET_FORWARD prio -150 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -150 -- chain POSTROUTING hook NF_INET_POST_ROUTING prio -150 -- } -- -- table filter { -- chain INPUT hook NF_INET_LOCAL_IN prio 0 -- chain FORWARD hook NF_INET_FORWARD prio 0 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio 0 -- } -- -- table nat { -- chain PREROUTING hook NF_INET_PRE_ROUTING prio -100 -- chain INPUT hook NF_INET_LOCAL_IN prio 100 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio -100 -- chain POSTROUTING hook NF_INET_POST_ROUTING prio 100 -- } -- -- table security { -- chain INPUT hook NF_INET_LOCAL_IN prio 50 -- chain FORWARD hook NF_INET_FORWARD prio 50 -- chain OUTPUT hook NF_INET_LOCAL_OUT prio 50 -- } --} -- --family arp { -- table filter { -- chain INPUT hook NF_ARP_IN prio 0 -- chain OUTPUT hook NF_ARP_OUT prio 0 -- } --} -diff --git a/iptables/xtables-multi.h b/iptables/xtables-multi.h -index 94c24d5a22c7e..833c11a2ac914 100644 ---- a/iptables/xtables-multi.h -+++ b/iptables/xtables-multi.h -@@ -20,7 +20,6 @@ extern int xtables_arp_save_main(int, char **); - extern int xtables_eb_main(int, char **); - extern int xtables_eb_restore_main(int, char **); - extern int xtables_eb_save_main(int, char **); --extern int xtables_config_main(int, char **); - extern int xtables_monitor_main(int, char **); - - extern struct xtables_globals arptables_globals; --- -2.40.0 - diff --git a/0049-Proper-fix-for-unknown-argument-error-message.patch b/0049-Proper-fix-for-unknown-argument-error-message.patch deleted file mode 100644 index cc76529..0000000 --- a/0049-Proper-fix-for-unknown-argument-error-message.patch +++ /dev/null @@ -1,148 +0,0 @@ -From 26e69aa7e332311ce1523c375a1afedf27add02c Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 25 Jan 2023 01:51:43 +0100 -Subject: [PATCH] Proper fix for "unknown argument" error message - -While commit 1b8210f848631 kind of fixed the corner-case of invalid -short-options packed with others, it broke error reporting for -long-options. Revert it and deploy a proper solution: - -When passing an invalid short-option, e.g. 'iptables -vaL', getopt_long -sets the variable 'optopt' to the invalid character's value. Use it for -reporting instead of optind if set. - -To distinguish between invalid options and missing option arguments, -ebtables-translate optstring needs adjustment. - -Fixes: 1b8210f848631 ("ebtables: Fix error message for invalid parameters") -Signed-off-by: Phil Sutter -(cherry picked from commit d6eb6a9fd3878ce4fa01f8d4127f1735988bd07b) ---- - .../testcases/iptables/0009-unknown-arg_0 | 31 +++++++++++++++++++ - iptables/xshared.c | 9 ++++-- - iptables/xtables-eb-translate.c | 8 ++--- - iptables/xtables-eb.c | 17 ++++++---- - 4 files changed, 50 insertions(+), 15 deletions(-) - create mode 100755 iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 - -diff --git a/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 b/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 -new file mode 100755 -index 0000000000000..ac6e743966196 ---- /dev/null -+++ b/iptables/tests/shell/testcases/iptables/0009-unknown-arg_0 -@@ -0,0 +1,31 @@ -+#!/bin/bash -+ -+rc=0 -+ -+check() { -+ local cmd="$1" -+ local msg="$2" -+ -+ $XT_MULTI $cmd 2>&1 | grep -q "$msg" || { -+ echo "cmd: $XT_MULTI $1" -+ echo "exp: $msg" -+ echo "res: $($XT_MULTI $cmd 2>&1)" -+ rc=1 -+ } -+} -+ -+cmds="iptables ip6tables" -+[[ $XT_MULTI == *xtables-nft-multi ]] && { -+ cmds+=" ebtables" -+ cmds+=" iptables-translate" -+ cmds+=" ip6tables-translate" -+ cmds+=" ebtables-translate" -+} -+ -+for cmd in $cmds; do -+ check "${cmd} --foo" 'unknown option "--foo"' -+ check "${cmd} -A" 'option "-A" requires an argument' -+ check "${cmd} -aL" 'unknown option "-a"' -+done -+ -+exit $rc -diff --git a/iptables/xshared.c b/iptables/xshared.c -index 7711af532f0a6..0fab205acfdcf 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -192,9 +192,12 @@ int command_default(struct iptables_command_state *cs, - if (cs->c == ':') - xtables_error(PARAMETER_PROBLEM, "option \"%s\" " - "requires an argument", cs->argv[optind-1]); -- if (cs->c == '?') -- xtables_error(PARAMETER_PROBLEM, "unknown option " -- "\"%s\"", cs->argv[optind-1]); -+ if (cs->c == '?') { -+ char optoptstr[3] = {'-', optopt, '\0'}; -+ -+ xtables_error(PARAMETER_PROBLEM, "unknown option \"%s\"", -+ optopt ? optoptstr : cs->argv[optind - 1]); -+ } - xtables_error(PARAMETER_PROBLEM, "Unknown arg \"%s\"", optarg); - } - -diff --git a/iptables/xtables-eb-translate.c b/iptables/xtables-eb-translate.c -index 86177024ec703..25fc08d8dd479 100644 ---- a/iptables/xtables-eb-translate.c -+++ b/iptables/xtables-eb-translate.c -@@ -201,7 +201,7 @@ static int do_commandeb_xlate(struct nft_handle *h, int argc, char *argv[], char - printf("nft "); - /* Getopt saves the day */ - while ((c = getopt_long(argc, argv, -- "-A:D:I:N:E:X::L::Z::F::P:Vhi:o:j:c:p:s:d:t:M:", opts, NULL)) != -1) { -+ "-:A:D:I:N:E:X::L::Z::F::P:Vhi:o:j:c:p:s:d:t:M:", opts, NULL)) != -1) { - cs.c = c; - switch (c) { - case 'A': /* Add a rule */ -@@ -491,11 +491,7 @@ static int do_commandeb_xlate(struct nft_handle *h, int argc, char *argv[], char - continue; - default: - ebt_check_inverse2(optarg, argc, argv); -- -- if (ebt_command_default(&cs)) -- xtables_error(PARAMETER_PROBLEM, -- "Unknown argument: '%s'", -- argv[optind - 1]); -+ ebt_command_default(&cs); - - if (command != 'A' && command != 'I' && - command != 'D') -diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c -index 78e21a88fa519..8c46c910eea46 100644 ---- a/iptables/xtables-eb.c -+++ b/iptables/xtables-eb.c -@@ -639,7 +639,16 @@ int ebt_command_default(struct iptables_command_state *cs) - return 0; - } - } -- return 1; -+ if (cs->c == ':') -+ xtables_error(PARAMETER_PROBLEM, "option \"%s\" " -+ "requires an argument", cs->argv[optind - 1]); -+ if (cs->c == '?') { -+ char optoptstr[3] = {'-', optopt, '\0'}; -+ -+ xtables_error(PARAMETER_PROBLEM, "unknown option \"%s\"", -+ optopt ? optoptstr : cs->argv[optind - 1]); -+ } -+ xtables_error(PARAMETER_PROBLEM, "Unknown arg \"%s\"", optarg); - } - - int nft_init_eb(struct nft_handle *h, const char *pname) -@@ -1078,11 +1087,7 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - continue; - default: - ebt_check_inverse2(optarg, argc, argv); -- -- if (ebt_command_default(&cs)) -- xtables_error(PARAMETER_PROBLEM, -- "Unknown argument: '%s'", -- argv[optind]); -+ ebt_command_default(&cs); - - if (command != 'A' && command != 'I' && - command != 'D' && command != 'C') --- -2.40.0 - diff --git a/0050-ebtables-Refuse-unselected-targets-options.patch b/0050-ebtables-Refuse-unselected-targets-options.patch deleted file mode 100644 index 0b70ff2..0000000 --- a/0050-ebtables-Refuse-unselected-targets-options.patch +++ /dev/null @@ -1,239 +0,0 @@ -From bf08ce5d9a8b3adf4688057c97a65820ba74c730 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Wed, 25 Jan 2023 02:01:56 +0100 -Subject: [PATCH] ebtables: Refuse unselected targets' options - -Unlike legacy, ebtables-nft would allow e.g.: - -| -t nat -A PREROUTING --to-dst fe:ed:00:00:ba:be - -While the result is correct, it may mislead users into believing -multiple targets are possible per rule. Better follow legacy's behaviour -and reject target options unless they have been "enabled" by a previous -'-j' option. - -To achieve this, one needs to distinguish targets from watchers also -attached to 'xtables_targets' and otherwise behaving like regular -matches. Introduce XTABLES_EXT_WATCHER to mark the two. - -The above works already, but error messages are misleading when using -the now unsupported syntax since target options have been merged -already. Solve this by not pre-loading the targets at all, code will -just fall back to loading ad '-j' parsing time as iptables does. - -Note how this also fixes for 'counter' statement being in wrong position -of ebtables-translate output. - -Fixes: fe97f60e5d2a9 ("ebtables-compat: add watchers support") -Signed-off-by: Phil Sutter -(cherry picked from commit 27d37863a486352511dac385bde8f3d20526be5b) - -Conflicts: - extensions/libebt_dnat.txlate - extensions/libebt_mark.txlate - extensions/libebt_snat.txlate --> Test cases manually adjusted, downstream misses the "quote whole - rule in translation" change. ---- - extensions/libebt_dnat.txlate | 12 ++++---- - extensions/libebt_log.c | 1 + - extensions/libebt_mark.txlate | 16 +++++----- - extensions/libebt_nflog.c | 1 + - extensions/libebt_snat.txlate | 8 ++--- - include/xtables.h | 1 + - .../ebtables/0002-ebtables-save-restore_0 | 4 +-- - iptables/xtables-eb.c | 29 +++++++------------ - 8 files changed, 33 insertions(+), 39 deletions(-) - -diff --git a/extensions/libebt_dnat.txlate b/extensions/libebt_dnat.txlate -index 2652dd55b2644..d99396a513b8d 100644 ---- a/extensions/libebt_dnat.txlate -+++ b/extensions/libebt_dnat.txlate -@@ -1,8 +1,8 @@ --ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter -+ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff -+nft add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff accept - --ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT --nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff accept counter -+ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff --dnat-target ACCEPT -+nft add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff accept - --ebtables-translate -t nat -A PREROUTING -i someport --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE --nft add rule bridge nat PREROUTING iifname "someport" ether daddr set de:ad:0:be:ee:ff continue counter -+ebtables-translate -t nat -A PREROUTING -i someport -j dnat --to-dst de:ad:00:be:ee:ff --dnat-target CONTINUE -+nft add rule bridge nat PREROUTING iifname "someport" counter ether daddr set de:ad:0:be:ee:ff continue -diff --git a/extensions/libebt_log.c b/extensions/libebt_log.c -index 8858cf0e22c00..9f95bf77d9288 100644 ---- a/extensions/libebt_log.c -+++ b/extensions/libebt_log.c -@@ -198,6 +198,7 @@ static int brlog_xlate(struct xt_xlate *xl, - static struct xtables_target brlog_target = { - .name = "log", - .revision = 0, -+ .ext_flags = XTABLES_EXT_WATCHER, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_log_info)), -diff --git a/extensions/libebt_mark.txlate b/extensions/libebt_mark.txlate -index 7529302d9a444..9695139655055 100644 ---- a/extensions/libebt_mark.txlate -+++ b/extensions/libebt_mark.txlate -@@ -1,11 +1,11 @@ --ebtables-translate -A INPUT --mark-set 42 --nft add rule bridge filter INPUT meta mark set 0x2a accept counter -+ebtables-translate -A INPUT -j mark --mark-set 42 -+nft add rule bridge filter INPUT counter meta mark set 0x2a accept - --ebtables-translate -A INPUT --mark-or 42 --mark-target RETURN --nft add rule bridge filter INPUT meta mark set meta mark or 0x2a return counter -+ebtables-translate -A INPUT -j mark --mark-or 42 --mark-target RETURN -+nft add rule bridge filter INPUT counter meta mark set meta mark or 0x2a return - --ebtables-translate -A INPUT --mark-and 42 --mark-target ACCEPT --nft add rule bridge filter INPUT meta mark set meta mark and 0x2a accept counter -+ebtables-translate -A INPUT -j mark --mark-and 42 --mark-target ACCEPT -+nft add rule bridge filter INPUT counter meta mark set meta mark and 0x2a accept - --ebtables-translate -A INPUT --mark-xor 42 --mark-target DROP --nft add rule bridge filter INPUT meta mark set meta mark xor 0x2a drop counter -+ebtables-translate -A INPUT -j mark --mark-xor 42 --mark-target DROP -+nft add rule bridge filter INPUT counter meta mark set meta mark xor 0x2a drop -diff --git a/extensions/libebt_nflog.c b/extensions/libebt_nflog.c -index 9801f358c81b1..23c9eed51d8e9 100644 ---- a/extensions/libebt_nflog.c -+++ b/extensions/libebt_nflog.c -@@ -150,6 +150,7 @@ static int brnflog_xlate(struct xt_xlate *xl, - static struct xtables_target brnflog_watcher = { - .name = "nflog", - .revision = 0, -+ .ext_flags = XTABLES_EXT_WATCHER, - .version = XTABLES_VERSION, - .family = NFPROTO_BRIDGE, - .size = XT_ALIGN(sizeof(struct ebt_nflog_info)), -diff --git a/extensions/libebt_snat.txlate b/extensions/libebt_snat.txlate -index 0d84602466c23..6b2250647daf3 100644 ---- a/extensions/libebt_snat.txlate -+++ b/extensions/libebt_snat.txlate -@@ -1,5 +1,5 @@ --ebtables-translate -t nat -A POSTROUTING -s 0:0:0:0:0:0 -o someport+ --to-source de:ad:00:be:ee:ff --nft add rule bridge nat POSTROUTING oifname "someport*" ether saddr 00:00:00:00:00:00 ether saddr set de:ad:0:be:ee:ff accept counter -+ebtables-translate -t nat -A POSTROUTING -s 0:0:0:0:0:0 -o someport+ -j snat --to-source de:ad:00:be:ee:ff -+nft add rule bridge nat POSTROUTING oifname "someport*" ether saddr 00:00:00:00:00:00 counter ether saddr set de:ad:0:be:ee:ff accept - --ebtables-translate -t nat -A POSTROUTING -o someport --to-src de:ad:00:be:ee:ff --snat-target CONTINUE --nft add rule bridge nat POSTROUTING oifname "someport" ether saddr set de:ad:0:be:ee:ff continue counter -+ebtables-translate -t nat -A POSTROUTING -o someport -j snat --to-src de:ad:00:be:ee:ff --snat-target CONTINUE -+nft add rule bridge nat POSTROUTING oifname "someport" counter ether saddr set de:ad:0:be:ee:ff continue -diff --git a/include/xtables.h b/include/xtables.h -index f1937f3ea0530..17ba396882d5a 100644 ---- a/include/xtables.h -+++ b/include/xtables.h -@@ -203,6 +203,7 @@ struct xtables_lmap { - - enum xtables_ext_flags { - XTABLES_EXT_ALIAS = 1 << 0, -+ XTABLES_EXT_WATCHER = 1 << 1, - }; - - struct xt_xlate; -diff --git a/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 b/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 -index ccdef19cfb215..a3fd4a6349019 100755 ---- a/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 -+++ b/iptables/tests/shell/testcases/ebtables/0002-ebtables-save-restore_0 -@@ -38,7 +38,7 @@ $XT_MULTI ebtables -A foo -p IPv6 --ip6-proto tcp -j ACCEPT - - $XT_MULTI ebtables -A foo --limit 100 --limit-burst 42 -j ACCEPT - $XT_MULTI ebtables -A foo --log --$XT_MULTI ebtables -A foo --mark-set 0x23 --mark-target ACCEPT -+$XT_MULTI ebtables -A foo -j mark --mark-set 0x23 --mark-target ACCEPT - $XT_MULTI ebtables -A foo --nflog - $XT_MULTI ebtables -A foo --pkttype-type multicast -j ACCEPT - $XT_MULTI ebtables -A foo --stp-type config -j ACCEPT -@@ -53,7 +53,7 @@ $XT_MULTI ebtables -A FORWARD -j foo - $XT_MULTI ebtables -N bar - $XT_MULTI ebtables -P bar RETURN - --$XT_MULTI ebtables -t nat -A PREROUTING --redirect-target ACCEPT -+$XT_MULTI ebtables -t nat -A PREROUTING -j redirect --redirect-target ACCEPT - #$XT_MULTI ebtables -t nat -A PREROUTING --to-src fe:ed:ba:be:00:01 - - $XT_MULTI ebtables -t nat -A OUTPUT -j ACCEPT -diff --git a/iptables/xtables-eb.c b/iptables/xtables-eb.c -index 8c46c910eea46..3b5b301d23a2a 100644 ---- a/iptables/xtables-eb.c -+++ b/iptables/xtables-eb.c -@@ -467,14 +467,14 @@ static void ebt_load_match(const char *name) - xtables_error(OTHER_PROBLEM, "Can't alloc memory"); - } - --static void __ebt_load_watcher(const char *name, const char *typename) -+static void ebt_load_watcher(const char *name) - { - struct xtables_target *watcher; - size_t size; - - watcher = xtables_find_target(name, XTF_TRY_LOAD); - if (!watcher) { -- fprintf(stderr, "Unable to load %s %s\n", name, typename); -+ fprintf(stderr, "Unable to load %s watcher\n", name); - return; - } - -@@ -495,16 +495,6 @@ static void __ebt_load_watcher(const char *name, const char *typename) - xtables_error(OTHER_PROBLEM, "Can't alloc memory"); - } - --static void ebt_load_watcher(const char *name) --{ -- return __ebt_load_watcher(name, "watcher"); --} -- --static void ebt_load_target(const char *name) --{ -- return __ebt_load_watcher(name, "target"); --} -- - void ebt_load_match_extensions(void) - { - opts = ebt_original_options; -@@ -521,13 +511,6 @@ void ebt_load_match_extensions(void) - - ebt_load_watcher("log"); - ebt_load_watcher("nflog"); -- -- ebt_load_target("mark"); -- ebt_load_target("dnat"); -- ebt_load_target("snat"); -- ebt_load_target("arpreply"); -- ebt_load_target("redirect"); -- ebt_load_target("standard"); - } - - void ebt_add_match(struct xtables_match *m, -@@ -632,6 +615,9 @@ int ebt_command_default(struct iptables_command_state *cs) - - /* Is it a watcher option? */ - for (t = xtables_targets; t; t = t->next) { -+ if (!(t->ext_flags & XTABLES_EXT_WATCHER)) -+ continue; -+ - if (t->parse && - t->parse(cs->c - t->option_offset, cs->argv, - ebt_invert, &t->tflags, NULL, &t->t)) { -@@ -725,6 +711,11 @@ int do_commandeb(struct nft_handle *h, int argc, char *argv[], char **table, - optind = 0; - opterr = false; - -+ for (t = xtables_targets; t; t = t->next) { -+ t->tflags = 0; -+ t->used = 0; -+ } -+ - /* Getopt saves the day */ - while ((c = getopt_long(argc, argv, EBT_OPTSTRING, - opts, NULL)) != -1) { --- -2.40.0 - diff --git a/0051-extensions-libebt_redirect-Fix-target-translation.patch b/0051-extensions-libebt_redirect-Fix-target-translation.patch deleted file mode 100644 index 7192909..0000000 --- a/0051-extensions-libebt_redirect-Fix-target-translation.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 21e9bacde3097fbbca404063f112bb741d404f06 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 31 Jan 2023 22:28:24 +0100 -Subject: [PATCH] extensions: libebt_redirect: Fix target translation - -While EBT_ACCEPT is the default verdict for ebtables targets, omitting -it from translation implicitly converts it into 'continue'. Omit the -non-default EBT_CONTINUE instead. - -Fixes: 24ce7465056ae ("ebtables-compat: add redirect match extension") -Signed-off-by: Phil Sutter -(cherry picked from commit bb6b243c481f90f7dc4a0bd89187ee2bb823f1f6) ---- - extensions/libebt_redirect.c | 2 +- - extensions/libebt_redirect.txlate | 8 ++++++++ - 2 files changed, 9 insertions(+), 1 deletion(-) - create mode 100644 extensions/libebt_redirect.txlate - -diff --git a/extensions/libebt_redirect.c b/extensions/libebt_redirect.c -index 4d4c7a02cea89..389f3ccb53f60 100644 ---- a/extensions/libebt_redirect.c -+++ b/extensions/libebt_redirect.c -@@ -84,7 +84,7 @@ static int brredir_xlate(struct xt_xlate *xl, - const struct ebt_redirect_info *red = (const void*)params->target->data; - - xt_xlate_add(xl, "meta set pkttype host"); -- if (red->target != EBT_ACCEPT) -+ if (red->target != EBT_CONTINUE) - xt_xlate_add(xl, " %s ", brredir_verdict(red->target)); - return 1; - } -diff --git a/extensions/libebt_redirect.txlate b/extensions/libebt_redirect.txlate -new file mode 100644 -index 0000000000000..f0dd5deaf6406 ---- /dev/null -+++ b/extensions/libebt_redirect.txlate -@@ -0,0 +1,8 @@ -+ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host accept' -+ -+ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target RETURN -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host return' -+ -+ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target CONTINUE -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host' --- -2.40.0 - diff --git a/0052-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch b/0052-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch deleted file mode 100644 index 44b919f..0000000 --- a/0052-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch +++ /dev/null @@ -1,48 +0,0 @@ -From f2865fcf843ae46919f9cd62158a0676c1b152c2 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 31 Jan 2023 23:32:50 +0100 -Subject: [PATCH] extensions: libebt_redirect: Fix for wrong syntax in - translation - -Meta key comes before 'set' in meta statement. - -Fixes: 24ce7465056ae ("ebtables-compat: add redirect match extension") -Signed-off-by: Phil Sutter -(cherry picked from commit 6d1263002c2a9fc6dfa59c764dee767a084d428d) ---- - extensions/libebt_redirect.c | 2 +- - extensions/libebt_redirect.txlate | 6 +++--- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/extensions/libebt_redirect.c b/extensions/libebt_redirect.c -index 389f3ccb53f60..7821935e137aa 100644 ---- a/extensions/libebt_redirect.c -+++ b/extensions/libebt_redirect.c -@@ -83,7 +83,7 @@ static int brredir_xlate(struct xt_xlate *xl, - { - const struct ebt_redirect_info *red = (const void*)params->target->data; - -- xt_xlate_add(xl, "meta set pkttype host"); -+ xt_xlate_add(xl, "meta pkttype set host"); - if (red->target != EBT_CONTINUE) - xt_xlate_add(xl, " %s ", brredir_verdict(red->target)); - return 1; -diff --git a/extensions/libebt_redirect.txlate b/extensions/libebt_redirect.txlate -index f0dd5deaf6406..d073ec774c4fa 100644 ---- a/extensions/libebt_redirect.txlate -+++ b/extensions/libebt_redirect.txlate -@@ -1,8 +1,8 @@ - ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host accept' -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host accept' - - ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target RETURN --nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host return' -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host return' - - ebtables-translate -t nat -A PREROUTING -d de:ad:00:00:be:ef -j redirect --redirect-target CONTINUE --nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta set pkttype host' -+nft 'add rule bridge nat PREROUTING ether daddr de:ad:00:00:be:ef counter meta pkttype set host' --- -2.40.0 - diff --git a/0053-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch b/0053-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch deleted file mode 100644 index 497eafc..0000000 --- a/0053-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 3a0dc287ed0f6acafbe353e1d6530d9e2f801dfe Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 3 Feb 2023 18:58:36 +0100 -Subject: [PATCH] extensions: libebt_ip: Do not use 'ip dscp' for translation - -Converting from TOS field match to DSCP one is irreversible, so replay -testing is not possible. Use a raw payload expression to produce -something that translates 1:1 back into an 'ip' match. - -Fixes: 03ecffe6c2cc0 ("ebtables-compat: add initial translations") -Signed-off-by: Phil Sutter -(cherry picked from commit 744c56bda974caaa274318d2825b3e43b55bf145) - -Conflicts: - extensions/libebt_ip.txlate --> Test case manually adjusted, downstream misses the "quote whole - rule in translation" change. ---- - extensions/libebt_ip.c | 4 ++-- - extensions/libebt_ip.txlate | 2 +- - 2 files changed, 3 insertions(+), 3 deletions(-) - -diff --git a/extensions/libebt_ip.c b/extensions/libebt_ip.c -index 51649ffb3c305..557cf2c1269c6 100644 ---- a/extensions/libebt_ip.c -+++ b/extensions/libebt_ip.c -@@ -678,10 +678,10 @@ static int brip_xlate(struct xt_xlate *xl, - brip_xlate_nh(xl, info, EBT_IP_DEST); - - if (info->bitmask & EBT_IP_TOS) { -- xt_xlate_add(xl, "ip dscp "); -+ xt_xlate_add(xl, "@nh,8,8 "); - if (info->invflags & EBT_IP_TOS) - xt_xlate_add(xl, "!= "); -- xt_xlate_add(xl, "0x%02x ", info->tos & 0x3f); /* remove ECN bits */ -+ xt_xlate_add(xl, "0x%02x ", info->tos); - } - if (info->bitmask & EBT_IP_PROTO) { - struct protoent *pe; -diff --git a/extensions/libebt_ip.txlate b/extensions/libebt_ip.txlate -index b5882c342b047..5c766e1b743ea 100644 ---- a/extensions/libebt_ip.txlate -+++ b/extensions/libebt_ip.txlate -@@ -5,7 +5,7 @@ ebtables-translate -I FORWARD -p ip --ip-dst 10.0.0.1 - nft insert rule bridge filter FORWARD ip daddr 10.0.0.1 counter - - ebtables-translate -I OUTPUT 3 -p ip -o eth0 --ip-tos 0xff --nft insert rule bridge filter OUTPUT oifname "eth0" ip dscp 0x3f counter -+nft insert rule bridge filter OUTPUT oifname "eth0" @nh,8,8 0xff counter - - ebtables-translate -A FORWARD -p ip --ip-proto tcp --ip-dport 22 - nft add rule bridge filter FORWARD tcp dport 22 counter --- -2.40.0 - diff --git a/0054-extensions-libebt_ip-Translation-has-to-match-on-eth.patch b/0054-extensions-libebt_ip-Translation-has-to-match-on-eth.patch deleted file mode 100644 index 63b1f76..0000000 --- a/0054-extensions-libebt_ip-Translation-has-to-match-on-eth.patch +++ /dev/null @@ -1,90 +0,0 @@ -From 67458075a1d61ab12d48df4d5b07d408c354d31b Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 3 Feb 2023 17:37:40 +0100 -Subject: [PATCH] extensions: libebt_ip: Translation has to match on ether type - -On one hand, nft refuses th expression in bridge family if layer3 -protocol has not been assured by a previous match. On the other, ebt_ip -kernel module will only match on IPv4 packets, so there might be a -functional change in the translation versus the original. - -Instead of just always emitting an 'ether type' match, decide whether -it's actually needed - explicit "ip " payload matches (or -icmp ones) cause implicit creation of a match on IPv4 by nft. - -Fixes: 03ecffe6c2cc0 ("ebtables-compat: add initial translations") -Signed-off-by: Phil Sutter -(cherry picked from commit b860e658200af8fdeced2896a1a6c2f0f0692b70) - -Conflicts: - extensions/libebt_ip.txlate --> Test case manually adjusted, downstream misses the "quote whole - rule in translation" change. ---- - extensions/libebt_ip.c | 21 +++++++++++++++++++++ - extensions/libebt_ip.txlate | 6 +++--- - 2 files changed, 24 insertions(+), 3 deletions(-) - -diff --git a/extensions/libebt_ip.c b/extensions/libebt_ip.c -index 557cf2c1269c6..db4b1d4d61fe8 100644 ---- a/extensions/libebt_ip.c -+++ b/extensions/libebt_ip.c -@@ -668,6 +668,24 @@ static void brip_xlate_nh(struct xt_xlate *xl, - xtables_ipmask_to_numeric(maskp)); - } - -+static bool may_skip_ether_type_dep(uint8_t flags) -+{ -+ /* these convert to "ip (s|d)addr" matches */ -+ if (flags & (EBT_IP_SOURCE | EBT_IP_DEST)) -+ return true; -+ -+ /* icmp match triggers implicit ether type dependency in nft */ -+ if (flags & EBT_IP_ICMP) -+ return true; -+ -+ /* allow if "ip protocol" match is created by brip_xlate() */ -+ if (flags & EBT_IP_PROTO && -+ !(flags & (EBT_IP_SPORT | EBT_IP_DPORT | EBT_IP_ICMP))) -+ return true; -+ -+ return false; -+} -+ - static int brip_xlate(struct xt_xlate *xl, - const struct xt_xlate_mt_params *params) - { -@@ -677,6 +695,9 @@ static int brip_xlate(struct xt_xlate *xl, - brip_xlate_nh(xl, info, EBT_IP_SOURCE); - brip_xlate_nh(xl, info, EBT_IP_DEST); - -+ if (!may_skip_ether_type_dep(info->bitmask)) -+ xt_xlate_add(xl, "ether type ip "); -+ - if (info->bitmask & EBT_IP_TOS) { - xt_xlate_add(xl, "@nh,8,8 "); - if (info->invflags & EBT_IP_TOS) -diff --git a/extensions/libebt_ip.txlate b/extensions/libebt_ip.txlate -index 5c766e1b743ea..cc42d2dbacf65 100644 ---- a/extensions/libebt_ip.txlate -+++ b/extensions/libebt_ip.txlate -@@ -5,13 +5,13 @@ ebtables-translate -I FORWARD -p ip --ip-dst 10.0.0.1 - nft insert rule bridge filter FORWARD ip daddr 10.0.0.1 counter - - ebtables-translate -I OUTPUT 3 -p ip -o eth0 --ip-tos 0xff --nft insert rule bridge filter OUTPUT oifname "eth0" @nh,8,8 0xff counter -+nft insert rule bridge filter OUTPUT oifname "eth0" ether type ip @nh,8,8 0xff counter - - ebtables-translate -A FORWARD -p ip --ip-proto tcp --ip-dport 22 --nft add rule bridge filter FORWARD tcp dport 22 counter -+nft add rule bridge filter FORWARD ether type ip tcp dport 22 counter - - ebtables-translate -A FORWARD -p ip --ip-proto udp --ip-sport 1024:65535 --nft add rule bridge filter FORWARD udp sport 1024-65535 counter -+nft add rule bridge filter FORWARD ether type ip udp sport 1024-65535 counter - - ebtables-translate -A FORWARD -p ip --ip-proto 253 - nft add rule bridge filter FORWARD ip protocol 253 counter --- -2.40.0 - diff --git a/0055-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch b/0055-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch deleted file mode 100644 index ae960d7..0000000 --- a/0055-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch +++ /dev/null @@ -1,67 +0,0 @@ -From 895ea1c74596ed218e9d0f2fb33bf8f5e02d7951 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Tue, 28 Feb 2023 18:09:25 +0100 -Subject: [PATCH] nft-restore: Fix for deletion of new, referenced rule - -Combining multiple corner-cases here: - -* Insert a rule before another new one which is not the first. Triggers - NFTNL_RULE_ID assignment of the latter. - -* Delete the referenced new rule in the same batch again. Causes - overwriting of the previously assigned RULE_ID. - -Consequently, iptables-nft-restore fails during *insert*, because the -reference is dangling. - -Reported-by: Eric Garver -Fixes: 760b35b46e4cc ("nft: Fix for add and delete of same rule in single batch") -Signed-off-by: Phil Sutter -Tested-by: Eric Garver -(cherry picked from commit 5fd85822bd12a02f1a921243f605fc6238d705b4) ---- - iptables/nft.c | 3 ++- - .../ipt-restore/0003-restore-ordering_0 | 16 ++++++++++++++++ - 2 files changed, 18 insertions(+), 1 deletion(-) - -diff --git a/iptables/nft.c b/iptables/nft.c -index 03f4d7b69cd4d..a1702ed6ed350 100644 ---- a/iptables/nft.c -+++ b/iptables/nft.c -@@ -2334,7 +2334,8 @@ static int __nft_rule_del(struct nft_handle *h, struct nftnl_rule *r) - - nftnl_rule_list_del(r); - -- if (!nftnl_rule_get_u64(r, NFTNL_RULE_HANDLE)) -+ if (!nftnl_rule_get_u64(r, NFTNL_RULE_HANDLE) && -+ !nftnl_rule_get_u32(r, NFTNL_RULE_ID)) - nftnl_rule_set_u32(r, NFTNL_RULE_ID, ++h->rule_id); - - obj = batch_rule_add(h, NFT_COMPAT_RULE_DELETE, r); -diff --git a/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 b/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 -index 3f1d229e915ff..5482b7ea17298 100755 ---- a/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 -+++ b/iptables/tests/shell/testcases/ipt-restore/0003-restore-ordering_0 -@@ -123,3 +123,19 @@ EXPECT='-A FORWARD -m comment --comment "rule 1" -j ACCEPT - -A FORWARD -m comment --comment "rule 3" -j ACCEPT' - - diff -u -Z <(echo -e "$EXPECT") <(ipt_show) -+ -+# test adding, referencing and deleting the same rule in a batch -+ -+$XT_MULTI iptables-restore < -Date: Wed, 29 Mar 2023 16:22:16 +0200 -Subject: [PATCH] nft-shared: Drop unused include - -Code does not refer to struct xt_comment_info anymore. - -Fixes: 3bb497c61d743 ("xtables: Fix for deleting rules with comment") -Signed-off-by: Phil Sutter -(cherry picked from commit 465470184950d9035dcd1101c1f413f8a2051427) ---- - iptables/nft-shared.c | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c -index 17c4489b508ba..f71943c8018e1 100644 ---- a/iptables/nft-shared.c -+++ b/iptables/nft-shared.c -@@ -21,7 +21,6 @@ - #include - - #include --#include - #include - #include - #include --- -2.40.0 - diff --git a/0057-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch b/0057-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch deleted file mode 100644 index 05d2206..0000000 --- a/0057-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 56c7f80dc3a767a45e168a9ef77c48be585f3b50 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 28 Apr 2023 14:33:43 +0200 -Subject: [PATCH] arptables: Fix parsing of inverted 'arp operation' match - -The wrong bit was set in 'invflags', probably due to copy'n'paste from -the previous case. - -Fixes: 84909d171585d ("xtables: bootstrap ARP compatibility layer for nftables") -Signed-off-by: Phil Sutter -(cherry picked from commit 092e4b022152addc94524e2ba0cb608dac1a3a08) ---- - iptables/nft-arp.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c -index af19510e58013..6f02ef40280f9 100644 ---- a/iptables/nft-arp.c -+++ b/iptables/nft-arp.c -@@ -240,7 +240,7 @@ static void nft_arp_parse_payload(struct nft_xt_ctx *ctx, - fw->arp.arhln = ar_hln; - fw->arp.arhln_mask = 0xff; - if (inv) -- fw->arp.invflags |= IPT_INV_ARPOP; -+ fw->arp.invflags |= IPT_INV_ARPHLN; - break; - default: - if (ctx->payload.offset == sizeof(struct arphdr)) { --- -2.40.0 - diff --git a/0058-arptables-Don-t-omit-standard-matches-if-inverted.patch b/0058-arptables-Don-t-omit-standard-matches-if-inverted.patch deleted file mode 100644 index 3970ff0..0000000 --- a/0058-arptables-Don-t-omit-standard-matches-if-inverted.patch +++ /dev/null @@ -1,42 +0,0 @@ -From 97a7471c7f37a78767e96bb22dd531fb9abb2856 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 28 Apr 2023 14:37:47 +0200 -Subject: [PATCH] arptables: Don't omit standard matches if inverted - -Inverted --h-len and --h-type matches were omitted from output by -accident if they matched on their standard value. - -Fixes: 84331e3ed3f8e ("arptables-nft: Don't print default h-len/h-type values") -Signed-off-by: Phil Sutter -(cherry picked from commit 79f93b0943fa0e46ba29bb476362634509eb594e) ---- - iptables/nft-arp.c | 6 ++++-- - 1 file changed, 4 insertions(+), 2 deletions(-) - -diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c -index 6f02ef40280f9..e01a98569e0c7 100644 ---- a/iptables/nft-arp.c -+++ b/iptables/nft-arp.c -@@ -401,7 +401,8 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs, - - after_devdst: - -- if (fw->arp.arhln_mask != 255 || fw->arp.arhln != 6) { -+ if (fw->arp.arhln_mask != 255 || fw->arp.arhln != 6 || -+ fw->arp.invflags & IPT_INV_ARPHLN) { - printf("%s%s", sep, fw->arp.invflags & IPT_INV_ARPHLN - ? "! " : ""); - printf("--h-length %d", fw->arp.arhln); -@@ -425,7 +426,8 @@ static void nft_arp_print_rule_details(const struct iptables_command_state *cs, - sep = " "; - } - -- if (fw->arp.arhrd_mask != 65535 || fw->arp.arhrd != htons(1)) { -+ if (fw->arp.arhrd_mask != 65535 || fw->arp.arhrd != htons(1) || -+ fw->arp.invflags & IPT_INV_ARPHRD) { - uint16_t tmp = ntohs(fw->arp.arhrd); - - printf("%s%s", sep, fw->arp.invflags & IPT_INV_ARPHRD --- -2.40.0 - diff --git a/0059-xshared-Fix-parsing-of-option-arguments-in-same-word.patch b/0059-xshared-Fix-parsing-of-option-arguments-in-same-word.patch deleted file mode 100644 index 10a0d83..0000000 --- a/0059-xshared-Fix-parsing-of-option-arguments-in-same-word.patch +++ /dev/null @@ -1,211 +0,0 @@ -From 867fbd135d6cee35dea066a48ed7972a57845375 Mon Sep 17 00:00:00 2001 -From: Phil Sutter -Date: Fri, 28 Apr 2023 14:41:08 +0200 -Subject: [PATCH] xshared: Fix parsing of option arguments in same word - -When merging commandline parsers, a decision between 'argv[optind - 1]' -and 'optarg' had to be made in some spots. While the implementation of -check_inverse() required the former, use of the latter allows for the -common syntax of '--opt=arg' or even '-oarg' as 'optarg' will point at -the suffix while 'argv[optind - 1]' will just point at the following -option. - -Fix the mess by making check_inverse() update optarg pointer if needed -so calling code may refer to and always correct 'optarg'. - -Fixes: 0af80a91b0a98 ("nft: Merge xtables-arp-standalone.c into xtables-standalone.c") -Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1677 -Signed-off-by: Phil Sutter -(cherry picked from commit 90a7a183a208b691810b8519cc57d3d9d3b7eb60) ---- - extensions/libarpt_standard.t | 2 ++ - extensions/libxt_standard.t | 3 ++ - iptables/xshared.c | 61 +++++++++++++++++------------------ - 3 files changed, 35 insertions(+), 31 deletions(-) - -diff --git a/extensions/libarpt_standard.t b/extensions/libarpt_standard.t -index e84a00b780488..007fa2b8335e8 100644 ---- a/extensions/libarpt_standard.t -+++ b/extensions/libarpt_standard.t -@@ -12,3 +12,5 @@ - -i lo --destination-mac 11:22:33:44:55:66;-i lo --dst-mac 11:22:33:44:55:66;OK - --source-mac Unicast;--src-mac 00:00:00:00:00:00/01:00:00:00:00:00;OK - ! --src-mac Multicast;! --src-mac 01:00:00:00:00:00/01:00:00:00:00:00;OK -+--src-mac=01:02:03:04:05:06 --dst-mac=07:08:09:0A:0B:0C --h-length=6 --opcode=Request --h-type=Ethernet --proto-type=ipv4;--src-mac 01:02:03:04:05:06 --dst-mac 07:08:09:0a:0b:0c --opcode 1 --proto-type 0x800;OK -+--src-mac ! 01:02:03:04:05:06 --dst-mac ! 07:08:09:0A:0B:0C --h-length ! 6 --opcode ! Request --h-type ! Ethernet --proto-type ! ipv4;! --src-mac 01:02:03:04:05:06 ! --dst-mac 07:08:09:0a:0b:0c ! --h-length 6 ! --opcode 1 ! --h-type 1 ! --proto-type 0x800;OK -diff --git a/extensions/libxt_standard.t b/extensions/libxt_standard.t -index 56d6da2e5884e..6ed978e442b80 100644 ---- a/extensions/libxt_standard.t -+++ b/extensions/libxt_standard.t -@@ -21,3 +21,6 @@ - -s 10.11.12.13/255.128.0.0;-s 10.0.0.0/9;OK - -s 10.11.12.13/255.0.255.0;-s 10.0.12.0/255.0.255.0;OK - -s 10.11.12.13/255.0.12.0;-s 10.0.12.0/255.0.12.0;OK -+:FORWARD -+--protocol=tcp --source=1.2.3.4 --destination=5.6.7.8/32 --in-interface=eth0 --out-interface=eth1 --jump=ACCEPT;-s 1.2.3.4/32 -d 5.6.7.8/32 -i eth0 -o eth1 -p tcp -j ACCEPT;OK -+-ptcp -s1.2.3.4 -d5.6.7.8/32 -ieth0 -oeth1 -jACCEPT;-s 1.2.3.4/32 -d 5.6.7.8/32 -i eth0 -o eth1 -p tcp -j ACCEPT;OK -diff --git a/iptables/xshared.c b/iptables/xshared.c -index 0fab205acfdcf..ea664cb389758 100644 ---- a/iptables/xshared.c -+++ b/iptables/xshared.c -@@ -1316,7 +1316,7 @@ static void check_empty_interface(struct xtables_args *args, const char *arg) - } - - static void check_inverse(struct xtables_args *args, const char option[], -- bool *invert, int *optidx, int argc) -+ bool *invert, int argc, char **argv) - { - switch (args->family) { - case NFPROTO_ARP: -@@ -1335,12 +1335,11 @@ static void check_inverse(struct xtables_args *args, const char option[], - xtables_error(PARAMETER_PROBLEM, - "Multiple `!' flags not allowed"); - *invert = true; -- if (optidx) { -- *optidx = *optidx + 1; -- if (argc && *optidx > argc) -- xtables_error(PARAMETER_PROBLEM, -- "no argument following `!'"); -- } -+ optind++; -+ if (optind > argc) -+ xtables_error(PARAMETER_PROBLEM, "no argument following `!'"); -+ -+ optarg = argv[optind - 1]; - } - - static const char *optstring_lookup(int family) -@@ -1550,16 +1549,16 @@ void do_parse(int argc, char *argv[], - * Option selection - */ - case 'p': -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_PROTOCOL, - &args->invflags, invert); - - /* Canonicalize into lower case */ -- for (cs->protocol = argv[optind - 1]; -+ for (cs->protocol = optarg; - *cs->protocol; cs->protocol++) - *cs->protocol = tolower(*cs->protocol); - -- cs->protocol = argv[optind - 1]; -+ cs->protocol = optarg; - args->proto = xtables_parse_protocol(cs->protocol); - - if (args->proto == 0 && -@@ -1573,17 +1572,17 @@ void do_parse(int argc, char *argv[], - break; - - case 's': -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_SOURCE, - &args->invflags, invert); -- args->shostnetworkmask = argv[optind - 1]; -+ args->shostnetworkmask = optarg; - break; - - case 'd': -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_DESTINATION, - &args->invflags, invert); -- args->dhostnetworkmask = argv[optind - 1]; -+ args->dhostnetworkmask = optarg; - break; - - #ifdef IPT_F_GOTO -@@ -1596,71 +1595,71 @@ void do_parse(int argc, char *argv[], - #endif - - case 2:/* src-mac */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_S_MAC, &args->invflags, - invert); -- args->src_mac = argv[optind - 1]; -+ args->src_mac = optarg; - break; - - case 3:/* dst-mac */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_D_MAC, &args->invflags, - invert); -- args->dst_mac = argv[optind - 1]; -+ args->dst_mac = optarg; - break; - - case 'l':/* hardware length */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_H_LENGTH, &args->invflags, - invert); -- args->arp_hlen = argv[optind - 1]; -+ args->arp_hlen = optarg; - break; - - case 8: /* was never supported, not even in arptables-legacy */ - xtables_error(PARAMETER_PROBLEM, "not supported"); - case 4:/* opcode */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_OPCODE, &args->invflags, - invert); -- args->arp_opcode = argv[optind - 1]; -+ args->arp_opcode = optarg; - break; - - case 5:/* h-type */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_H_TYPE, &args->invflags, - invert); -- args->arp_htype = argv[optind - 1]; -+ args->arp_htype = optarg; - break; - - case 6:/* proto-type */ -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_P_TYPE, &args->invflags, - invert); -- args->arp_ptype = argv[optind - 1]; -+ args->arp_ptype = optarg; - break; - - case 'j': - set_option(&cs->options, OPT_JUMP, &args->invflags, - invert); -- command_jump(cs, argv[optind - 1]); -+ command_jump(cs, optarg); - break; - - case 'i': - check_empty_interface(args, optarg); -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_VIANAMEIN, - &args->invflags, invert); -- xtables_parse_interface(argv[optind - 1], -+ xtables_parse_interface(optarg, - args->iniface, - args->iniface_mask); - break; - - case 'o': - check_empty_interface(args, optarg); -- check_inverse(args, optarg, &invert, &optind, argc); -+ check_inverse(args, optarg, &invert, argc, argv); - set_option(&cs->options, OPT_VIANAMEOUT, - &args->invflags, invert); -- xtables_parse_interface(argv[optind - 1], -+ xtables_parse_interface(optarg, - args->outiface, - args->outiface_mask); - break; --- -2.40.0 - diff --git a/arptables-nft-helper b/arptables-helper similarity index 100% rename from arptables-nft-helper rename to arptables-helper diff --git a/arptables.service b/arptables.service new file mode 100644 index 0000000..df6c7d6 --- /dev/null +++ b/arptables.service @@ -0,0 +1,12 @@ +[Unit] +Description=Automates a packet filtering firewall with arptables +After=network.target + +[Service] +Type=oneshot +ExecStart=/usr/libexec/arptables-helper start +ExecStop=/usr/libexec/arptables-helper stop +RemainAfterExit=yes + +[Install] +WantedBy=multi-user.target diff --git a/coreteam-gpg-key-0xD70D1A666ACF2B21.txt b/coreteam-gpg-key-0xD70D1A666ACF2B21.txt new file mode 100644 index 0000000..cd4a35b --- /dev/null +++ b/coreteam-gpg-key-0xD70D1A666ACF2B21.txt @@ -0,0 +1,64 @@ +-----BEGIN PGP PUBLIC KEY BLOCK----- + +mQINBGcLlIQBEADH+pWx2d5XgY2JCOHTVaOpbNlNfp1k9Ul0W5zaZ7EFHIGSj06E +o3+OM0eI6+d51PnqwRE+WbV4T3ooGnfgXN4fmKgq2TwkxlhKeFSzNGMuzzuoEwD+ +2cvSF9VIrwif1o9oa9KMNfKTY/qjuWZS0QWZ08thPAf/tWpoaA3gaqYQUshj5G3w +nTMdYlHUj7wkZCMg63tDygAe/7fDT3zurKCMbFoyiyQkp7V1SLxZpvuyuyPH6HtQ +P5xcbXsp5ots0BgN+BplMX89DrspxJXqi7AsTf4QnC78KbchMJJxLKZQS759dQHF +qHUTb3YdlxXFou6Si5LiBzvmqBRFj6m/WV1a8mDy5fPDkOLoTCUFHLmgvYHPJdtK +5EqNkwYAbSnZKe9aSeVa4XhaZqyyQb9vIsKyOnwdJ/l222J95qHQapZSLcRdqgQz +ZgxuEdOHacEaJ1IJ21CE8EtJfFA5DMZtkZNIGF3OFlXhw7YxJoPgsodtlVspQsfX +u2FGP9yg0fd4zLgHnotKqfJQ9ZjMB6bbJUd6Au9jv0SiM+kVGeVfyaaX7TDeQ3TT +/e44uFvkHkbYFQPcqsTalxtre6v7pMG2iu2mbkhQOC7qbL5MKMSdA93w/lF7w20b +cwyDavEoKk9vgDjSkVjaffvdy4cESa5JY4lM4ZmzoujnAZMwbzQeGcBtqQARAQAB +tCxOZXRmaWx0ZXIgQ29yZSBUZWFtIDxjb3JldGVhbUBuZXRmaWx0ZXIub3JnPokC +VAQTAQoAPhYhBIxfcUahdXpl4kIqlNcNGmZqzyshBQJnC5SEAhsDBQkHhM4ABQsJ +CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJENcNGmZqzyshRE4P/AknD3DAWuCT7x7L +LFIUCkfl7WUou9zMQKy62JRK/+/lNyG1dkmvBu7XWLl/+IRv1uIb25I4xwaze6GF +8yhZDNXZLhUjComr864fMEdKNdXInAClLRNY0InkFmHw/SizvwDld4PgsLzoS+qL +5JY4FBlYEnd4wlIwH/w3gPycmdmQNVOjeWJhDrYKGLnjolpGRQPYRME4kjasWPbK +AWG/lpINQEB1DgtK8e6kcbUA8wSU6MMEsJjPY0o7lr9NvPfRpPXq34LjoFUXk3Hi +Bt8OuVVMo+wTmlZWkXdknFKS4IPVxUA53oJOVMFW8divmF/l676KBogSnczoX4vR +VW8sgDEKqb0NicKWJ2Fou+/KueY5OXsO8aZrZtXOsXIAMberdrNDYhyTUSYF8mZF +RdL6Jcm5GbQB/zOQElgzMwPQq5AD7SkziMzGOusWjqGmu9qphed/FimVbyRhMl5B +uDvGHthhy1KlPkqVcddN6i3/Kd/AMqXAuWMZH9FXJkUUWe+VAyeNHfEuBtSK2rqE +zf8TYGg5Gz+oNspWuqEyWUwoH7eQkRx2GIbwu2rwcIzrh8L0rsyu+6FNNHnQfnNq +ytbE888dxKkXeJ5T09Pp/hPwkNM8X8ZLcTTsAknrvqLNp2As49dP6iJwysfYLf/v +3Cyvz23JNeSQiTcC4YfKLs4LtCFkiQIzBBABCgAdFiEEN9lkrMBJgcdVAPub1V2X +iooUIOQFAmcLlJ0ACgkQ1V2XiooUIOQGJRAAsz/jYoNkSAhzvrY1t/5kSaa3Hyqi +wpaJNIb6YCNT9JFlEvfsIlikjK28I+LNqVrWoLZyX1np8h0AGfNUPo/rLzVXzqZ/ +UHZi5AjzXM6BVnR84LahFVVLISBtjt3DvY4xvl8cIh03ShJe/yAKIXZUbxXevtnj +M0/5bLaLjlVf3KldR+gFjUaTT1nxfkQnzxbk2yKe+1tuQzFsYPLG9Elzyagb4QYm +97CTxim3QcO0qWweoeusBqCkh7qD/ght76JrSnzq859XS//2jaq3A5ZsX5UJk5/E +FkzL4zersQZwQE10BByBBJbxC8DzMuGeV+eTVVHKU81cEnzZFxfyOtQBD+oHBauW +IC/v509TiH4qhZshJwcznsDZK1xAxxm3mryVtHbfSDSqzc5r/kNQt9mijD6wdsRb +0yQy1P2xkk1zyvOw3BRI2NVXq6+642cp21tjsY136JT/3a6KwIlIIdzIUqejbLoF +GgGZPJiQXthfmLpDgvduD6YgaSHyhtJesX3SIGvYBdCGT69blrB7lHazYRE/xKNu +bhnVzsaWlOXg52ChAMzsAAi5DV1669xUqRgj7zJHUq72bItZWdAvDSTIrQB4z7u8 +QW+XZsveWM2sKjzpLZjQaxdS7dFvGepYY5liA01w7Bx2lU75ejgaWrm/hlaT//RD +Al9IQzw14mOtm0e5Ag0EZwuUhAEQANmO+fv67llu3nOZh9mcTbKa0MTT6cNjpEVU +3MDImbN7pKTc/P+s6TVYBYn1q1U0XTXQlfh2HGdrLebAOdWW0Wcz4Kj9oOlRHOAR +yq3mRzb9hiCB89mJcw5xNIn83d5L/IJqONSaVLKnTwfwnTVaCJYuF5yIqDMOSXgS +C3sbGLx/yEchAhQEWUG8nm9WTybFfq98mFrHEKRGsSgfCHq6KMNn9NuhW149ZK+K +klPXZqFyDoRHdyivt9j9hfA0lr4t6sfXEfJedzjNO2f0Z8r2sQhmw3ykYDkzEF8I +zkgiik1Ke4+TmpD/4uL/hfgbkoVxZV6gI3M9rqs5o1glAuSFjsrGyog1EkUXplST +Qn4ea/vQ6t1iBkTb2r3qzhK+VL7GWlvZa9DGq8btNAiOjKKqa0+3zRTXyPJAdMQM +X+FBAhmaHJoylArEHdzv5haB7rv0aGjKV4O1ifonSGE2pllmSDbTO3exIeslLgDh +5GqVmQW30K5JvecKnb871c0utzRLHBF34HOYgRWBcl18DGD+SzXKj1//+4AatcAB +woNJHTEh6N3/mD3fJyWkyMwLJzo1x43Pmm1DkzioO9VMSxG7ReaH9WRDty3R83gT +njEI0CDkG7m0nXctrsDcmBCYMSnvriWVr7kNYQ9tSi9WUa8Cs0xCmy49fF+7ihIl +yANR2aMrABEBAAGJAjwEGAEKACYWIQSMX3FGoXV6ZeJCKpTXDRpmas8rIQUCZwuU +hAIbDAUJB4TOAAAKCRDXDRpmas8rIZPuD/4qYhAdmCtaicOjeuMI0EhKA0O0cnXv +BRwKXKGISZ6bt/f5fify78NQ4VdQzcpsRk1VvaEHRF5H+qxCQJ8MdzKcYpolCphj +ir1gE+zNP7gtzH4HOBzz3/q6GK5HmqwWth3X35ySrgrhnUZZX+plm9gRIRIqmijh +hdDp/3/2FcskQzr9UvIQDB14TbbSVAsDx5cQUM5F1nS1AAJNSrebuEcBeeM0N1HP +tqWmcJuAHtTlk+K5yk02cgbP9926vlty1uI46UyI4t/xOxmIY6gXlcSMbBnVmB0s +E+sKJTE7QrDpRRNiseCNLZcr/TNp9lrFpaUXz/JwXc+c1VC8UmARk9NLHsfoGz5H +fvhiUwl96wtvu1YKIev9nfVp1bb3/XeNAVJd+hNxOlkv68s3feutvv7vQR14E8cv +CVTXK7aAZKkWJl2n8pPohsXs5vwrsG36oFSH98jehLtzLrpgtWj6N7U8SWhI9JlT +EaIpEL/C1foVJeSZs8Tq1sqYaw81lovDFk8wuS1eFhWeEVodJQsfCPBgsQGZ46oZ +gWz3AU3KrB4ruNxjkJJxfgKu39pHDrv3o5ZufAHoIAHRdPTPlcH1Wi/1LLgLqHVC +9+i7N1ClsO1/VgtYmZwzxWxsEJOcE2+vOROoVzgMh5lGhCLh6/3VTL96hIjcMp4W +oD8ElPP+m/v6iA== +=70vD +-----END PGP PUBLIC KEY BLOCK----- diff --git a/ebtables-config b/ebtables-config new file mode 100644 index 0000000..69d9289 --- /dev/null +++ b/ebtables-config @@ -0,0 +1,11 @@ +# Save current firewall rules on stop. +# Value: yes|no, default: no +# Saves all firewall rules if firewall gets stopped +# (e.g. on system shutdown). +EBTABLES_SAVE_ON_STOP="no" + +# Save (and restore) rule counters. +# Value: yes|no, default: no +# Save rule counters when saving a kernel table to a file. If the +# rule counters were saved, they will be restored when restoring the table. +EBTABLES_SAVE_COUNTER="no" diff --git a/ebtables-helper b/ebtables-helper new file mode 100644 index 0000000..e63bd2b --- /dev/null +++ b/ebtables-helper @@ -0,0 +1,102 @@ +#!/bin/bash + +# compat for removed initscripts dependency + +success() { + echo "[ OK ]" + return 0 +} + +failure() { + echo "[FAILED]" + return 1 +} + +# internal variables +EBTABLES_CONFIG=/etc/sysconfig/ebtables-config +EBTABLES_DATA=/etc/sysconfig/ebtables +EBTABLES_TABLES="broute filter nat" +VAR_SUBSYS_EBTABLES=/var/lock/subsys/ebtables + +# ebtables-config defaults +EBTABLES_SAVE_ON_STOP="no" +EBTABLES_SAVE_ON_RESTART="no" +EBTABLES_SAVE_COUNTER="no" + +# load config if existing +[ -f "$EBTABLES_CONFIG" ] && . "$EBTABLES_CONFIG" + +initialize() { + local ret=0 + for table in $EBTABLES_TABLES; do + ebtables -t $table --init-table || ret=1 + done + return $ret +} + +sanitize_dump() { + local drop=false + + export EBTABLES_TABLES + + cat $1 | while read line; do + case $line in + \**) + drop=false + local table="${line#\*}" + local found=false + for t in $EBTABLES_TABLES; do + if [[ $t == $table ]]; then + found=true + break + fi + done + $found || drop=true + ;; + esac + $drop || echo "$line" + done +} + +start() { + if [ -f $EBTABLES_DATA ]; then + echo -n $"ebtables: loading ruleset from $EBTABLES_DATA: " + sanitize_dump $EBTABLES_DATA | ebtables-restore + else + echo -n $"ebtables: no stored ruleset, initializing empty tables: " + initialize + fi + local ret=$? + touch $VAR_SUBSYS_EBTABLES + return $ret +} + +save() { + echo -n $"ebtables: saving active ruleset to $EBTABLES_DATA: " + export EBTABLES_SAVE_COUNTER + ebtables-save >$EBTABLES_DATA && success || failure +} + +case $1 in + start) + [ -f "$VAR_SUBSYS_EBTABLES" ] && exit 0 + start && success || failure + RETVAL=$? + ;; + stop) + [ "x$EBTABLES_SAVE_ON_STOP" = "xyes" ] && save + echo -n $"ebtables: stopping firewall: " + initialize && success || failure + RETVAL=$? + rm -f $VAR_SUBSYS_EBTABLES + ;; + save) + save + ;; + *) + echo "usage: ${0##*/} {start|stop|save}" >&2 + RETVAL=2 + ;; +esac + +exit $RETVAL diff --git a/ebtables.service b/ebtables.service new file mode 100644 index 0000000..b096f1d --- /dev/null +++ b/ebtables.service @@ -0,0 +1,11 @@ +[Unit] +Description=Ethernet Bridge Filtering tables + +[Service] +Type=oneshot +RemainAfterExit=yes +ExecStart=/usr/libexec/ebtables-helper start +ExecStop=/usr/libexec/ebtables-helper stop + +[Install] +WantedBy=multi-user.target diff --git a/iptables-1.8.11-command-options-fix.patch b/iptables-1.8.11-command-options-fix.patch new file mode 100644 index 0000000..f6eecb1 --- /dev/null +++ b/iptables-1.8.11-command-options-fix.patch @@ -0,0 +1,27 @@ +commit 192c3a6bc18f206895ec5e38812d648ccfe7e281 +Author: Phil Sutter +Date: Wed Apr 23 12:36:13 2025 +0200 + + xshared: Accept an option if any given command allows it + + Fixed commit made option checking overly strict: Some commands may be + commbined (foremost --list and --zero), reject a given option only if it + is not allowed by any of the given commands. + + Reported-by: Adam Nielsen + Fixes: 9c09d28102bb4 ("xshared: Simplify generic_opt_check()") + Signed-off-by: Phil Sutter + +diff --git a/iptables/xshared.c b/iptables/xshared.c +index cdfd11ab..fc61e0fd 100644 +--- a/iptables/xshared.c ++++ b/iptables/xshared.c +@@ -980,7 +980,7 @@ static void generic_opt_check(struct xt_cmd_parse_ops *ops, + */ + for (i = 0, optval = 1; i < NUMBER_OF_OPT; optval = (1 << ++i)) { + if ((options & optval) && +- (options_v_commands[i] & command) != command) ++ !(options_v_commands[i] & command)) + xtables_error(PARAMETER_PROBLEM, + "Illegal option `%s' with this command", + ops->option_name(optval)); diff --git a/iptables-1.8.11-fix-interface-comparisons.patch b/iptables-1.8.11-fix-interface-comparisons.patch new file mode 100644 index 0000000..b038616 --- /dev/null +++ b/iptables-1.8.11-fix-interface-comparisons.patch @@ -0,0 +1,172 @@ +From 40406dbfaefbc204134452b2747bae4f6a122848 Mon Sep 17 00:00:00 2001 +From: Jeremy Sowden +Date: Mon, 18 Nov 2024 13:56:50 +0000 +Subject: nft: fix interface comparisons in `-C` commands + +Commit 9ccae6397475 ("nft: Leave interface masks alone when parsing from +kernel") removed code which explicitly set interface masks to all ones. The +result of this is that they are zero. However, they are used to mask interfaces +in `is_same_interfaces`. Consequently, the masked values are alway zero, the +comparisons are always true, and check commands which ought to fail succeed: + + # iptables -N test + # iptables -A test -i lo \! -o lo -j REJECT + # iptables -v -L test + Chain test (0 references) + pkts bytes target prot opt in out source destination + 0 0 REJECT all -- lo !lo anywhere anywhere reject-with icmp-port-unreachable + # iptables -v -C test -i abcdefgh \! -o abcdefgh -j REJECT + REJECT all opt -- in lo out !lo 0.0.0.0/0 -> 0.0.0.0/0 reject-with icmp-port-unreachable + +Remove the mask parameters from `is_same_interfaces`. Add a test-case. + +Fixes: 9ccae6397475 ("nft: Leave interface masks alone when parsing from kernel") +Signed-off-by: Jeremy Sowden +Signed-off-by: Phil Sutter +--- + iptables/nft-arp.c | 10 ++---- + iptables/nft-ipv4.c | 4 +-- + iptables/nft-ipv6.c | 6 +--- + iptables/nft-shared.c | 36 +++++----------------- + iptables/nft-shared.h | 6 +--- + .../testcases/nft-only/0020-compare-interfaces_0 | 9 ++++++ + 6 files changed, 22 insertions(+), 49 deletions(-) + create mode 100755 iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 + +diff --git a/iptables/nft-arp.c b/iptables/nft-arp.c +index 264864c3..c11d64c3 100644 +--- a/iptables/nft-arp.c ++++ b/iptables/nft-arp.c +@@ -385,14 +385,8 @@ static bool nft_arp_is_same(const struct iptables_command_state *cs_a, + return false; + } + +- return is_same_interfaces(a->arp.iniface, +- a->arp.outiface, +- (unsigned char *)a->arp.iniface_mask, +- (unsigned char *)a->arp.outiface_mask, +- b->arp.iniface, +- b->arp.outiface, +- (unsigned char *)b->arp.iniface_mask, +- (unsigned char *)b->arp.outiface_mask); ++ return is_same_interfaces(a->arp.iniface, a->arp.outiface, ++ b->arp.iniface, b->arp.outiface); + } + + static void nft_arp_save_chain(const struct nftnl_chain *c, const char *policy) +diff --git a/iptables/nft-ipv4.c b/iptables/nft-ipv4.c +index 74092875..0c8bd291 100644 +--- a/iptables/nft-ipv4.c ++++ b/iptables/nft-ipv4.c +@@ -113,9 +113,7 @@ static bool nft_ipv4_is_same(const struct iptables_command_state *a, + } + + return is_same_interfaces(a->fw.ip.iniface, a->fw.ip.outiface, +- a->fw.ip.iniface_mask, a->fw.ip.outiface_mask, +- b->fw.ip.iniface, b->fw.ip.outiface, +- b->fw.ip.iniface_mask, b->fw.ip.outiface_mask); ++ b->fw.ip.iniface, b->fw.ip.outiface); + } + + static void nft_ipv4_set_goto_flag(struct iptables_command_state *cs) +diff --git a/iptables/nft-ipv6.c b/iptables/nft-ipv6.c +index b184f8af..4dbb2af2 100644 +--- a/iptables/nft-ipv6.c ++++ b/iptables/nft-ipv6.c +@@ -99,11 +99,7 @@ static bool nft_ipv6_is_same(const struct iptables_command_state *a, + } + + return is_same_interfaces(a->fw6.ipv6.iniface, a->fw6.ipv6.outiface, +- a->fw6.ipv6.iniface_mask, +- a->fw6.ipv6.outiface_mask, +- b->fw6.ipv6.iniface, b->fw6.ipv6.outiface, +- b->fw6.ipv6.iniface_mask, +- b->fw6.ipv6.outiface_mask); ++ b->fw6.ipv6.iniface, b->fw6.ipv6.outiface); + } + + static void nft_ipv6_set_goto_flag(struct iptables_command_state *cs) +diff --git a/iptables/nft-shared.c b/iptables/nft-shared.c +index 6775578b..2c29e68f 100644 +--- a/iptables/nft-shared.c ++++ b/iptables/nft-shared.c +@@ -220,36 +220,16 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, + } + + bool is_same_interfaces(const char *a_iniface, const char *a_outiface, +- unsigned const char *a_iniface_mask, +- unsigned const char *a_outiface_mask, +- const char *b_iniface, const char *b_outiface, +- unsigned const char *b_iniface_mask, +- unsigned const char *b_outiface_mask) ++ const char *b_iniface, const char *b_outiface) + { +- int i; +- +- for (i = 0; i < IFNAMSIZ; i++) { +- if (a_iniface_mask[i] != b_iniface_mask[i]) { +- DEBUGP("different iniface mask %x, %x (%d)\n", +- a_iniface_mask[i] & 0xff, b_iniface_mask[i] & 0xff, i); +- return false; +- } +- if ((a_iniface[i] & a_iniface_mask[i]) +- != (b_iniface[i] & b_iniface_mask[i])) { +- DEBUGP("different iniface\n"); +- return false; +- } +- if (a_outiface_mask[i] != b_outiface_mask[i]) { +- DEBUGP("different outiface mask\n"); +- return false; +- } +- if ((a_outiface[i] & a_outiface_mask[i]) +- != (b_outiface[i] & b_outiface_mask[i])) { +- DEBUGP("different outiface\n"); +- return false; +- } ++ if (strncmp(a_iniface, b_iniface, IFNAMSIZ)) { ++ DEBUGP("different iniface\n"); ++ return false; ++ } ++ if (strncmp(a_outiface, b_outiface, IFNAMSIZ)) { ++ DEBUGP("different outiface\n"); ++ return false; + } +- + return true; + } + +diff --git a/iptables/nft-shared.h b/iptables/nft-shared.h +index 51d1e460..b57aee1f 100644 +--- a/iptables/nft-shared.h ++++ b/iptables/nft-shared.h +@@ -105,11 +105,7 @@ void add_l4proto(struct nft_handle *h, struct nftnl_rule *r, uint8_t proto, uint + void add_compat(struct nftnl_rule *r, uint32_t proto, bool inv); + + bool is_same_interfaces(const char *a_iniface, const char *a_outiface, +- unsigned const char *a_iniface_mask, +- unsigned const char *a_outiface_mask, +- const char *b_iniface, const char *b_outiface, +- unsigned const char *b_iniface_mask, +- unsigned const char *b_outiface_mask); ++ const char *b_iniface, const char *b_outiface); + + void __get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, uint8_t *op); + void get_cmp_data(struct nftnl_expr *e, void *data, size_t dlen, bool *inv); +diff --git a/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 +new file mode 100755 +index 00000000..278cd648 +--- /dev/null ++++ b/iptables/tests/shell/testcases/nft-only/0020-compare-interfaces_0 +@@ -0,0 +1,9 @@ ++#!/bin/bash ++ ++[[ $XT_MULTI == *xtables-nft-multi ]] || { echo "skip $XT_MULTI"; exit 0; } ++ ++$XT_MULTI iptables -N test ++$XT_MULTI iptables -A test -i lo \! -o lo -j REJECT ++$XT_MULTI iptables -C test -i abcdefgh \! -o abcdefgh -j REJECT 2>/dev/null && exit 1 ++ ++exit 0 +-- +cgit v1.2.3 + diff --git a/iptables.spec b/iptables.spec index 3b799d4..c999d94 100644 --- a/iptables.spec +++ b/iptables.spec @@ -10,83 +10,35 @@ Name: iptables Summary: Tools for managing Linux kernel packet filtering capabilities URL: https://www.netfilter.org/projects/iptables -Version: 1.8.8 -Release: 5%{?dist} -Source: %{url}/files/%{name}-%{version}.tar.bz2 -Source1: iptables.init -Source2: iptables-config -Source3: iptables.service -Source4: sysconfig_iptables -Source5: sysconfig_ip6tables -Source6: arptables-nft-helper - -Patch01: 0001-xshared-Fix-build-for-Werror-format-security.patch -Patch02: 0002-Revert-fix-build-for-missing-ETH_ALEN-definition.patch -Patch03: 0003-build-Fix-error-during-out-of-tree-build.patch -Patch04: 0004-libxtables-Unexport-init_extensions-declarations.patch -Patch05: 0005-iptables-legacy-Drop-redundant-include-of-xtables-mu.patch -Patch06: 0006-extensions-string-Do-not-print-default-to-value.patch -Patch07: 0007-nft-Exit-if-nftnl_alloc_expr-fails.patch -Patch08: 0008-xtables-monitor-add-missing-spaces-in-printed-str.patch -Patch09: 0009-libxtables-Fix-unsupported-extension-warning-corner-.patch -Patch10: 0010-nft-fix-ebtables-among-match-when-mac-ip-addresses-a.patch -Patch11: 0011-ebtables-Drop-unused-OPT_-defines.patch -Patch12: 0012-ebtables-Eliminate-OPT_TABLE.patch -Patch13: 0013-ebtables-Merge-OPT_-flags-with-xshared-ones.patch -Patch14: 0014-extensions-among-Remove-pointless-fall-through.patch -Patch15: 0015-extensions-among-Fix-for-use-with-ebtables-restore.patch -Patch16: 0016-extensions-libebt_stp-Eliminate-duplicate-space-in-o.patch -Patch17: 0017-extensions-libip6t_dst-Fix-output-for-empty-options.patch -Patch18: 0018-extensions-TCPOPTSTRIP-Do-not-print-empty-options.patch -Patch19: 0019-tests-IDLETIMER.t-Fix-syntax-support-for-restore-inp.patch -Patch20: 0020-tests-libebt_stp.t-Drop-duplicate-whitespace.patch -Patch21: 0021-libiptc-Fix-for-segfault-when-renaming-a-chain.patch -Patch22: 0022-extensions-DNAT-Fix-bad-IP-address-error-reporting.patch -Patch23: 0023-extensions-libebt_mark-Fix-mark-target-xlate.patch -Patch24: 0024-extensions-libebt_mark-Fix-xlate-test-case.patch -Patch25: 0025-extensions-libebt_redirect-Fix-xlate-return-code.patch -Patch26: 0026-extensions-libipt_ttl-Sanitize-xlate-callback.patch -Patch27: 0027-extensions-CONNMARK-Fix-xlate-callback.patch -Patch28: 0028-extensions-MARK-Sanitize-MARK_xlate.patch -Patch29: 0029-extensions-TCPMSS-Use-xlate-callback-for-IPv6-too.patch -Patch30: 0030-extensions-TOS-Fix-v1-xlate-callback.patch -Patch31: 0031-extensions-ecn-Sanitize-xlate-callback.patch -Patch32: 0032-extensions-libxt_conntrack-Drop-extra-whitespace-in-.patch -Patch33: 0033-iptables-restore-Free-handle-with-test-also.patch -Patch34: 0034-iptables-xml-Free-allocated-chain-strings.patch -Patch35: 0035-nft-Plug-memleak-in-nft_rule_zero_counters.patch -Patch36: 0036-xtables-Introduce-xtables_clear_iptables_command_sta.patch -Patch37: 0037-iptables-Properly-clear-iptables_command_state-objec.patch -Patch38: 0038-libiptc-Eliminate-garbage-access.patch -Patch39: 0039-nft-Fix-for-comparing-ifname-matches-against-nft-gen.patch -Patch40: 0040-nft-Fix-match-generator-for-i.patch -Patch41: 0041-xtables-translate-Fix-for-interfaces-with-asterisk-m.patch -Patch42: 0042-ebtables-Fix-MAC-address-match-translation.patch -Patch43: 0043-Drop-libiptc-linux_stddef.h.patch -Patch44: 0044-include-Makefile-xtables-version.h-is-generated.patch -Patch45: 0045-extensions-libxt_conntrack-remove-always-false-condi.patch -Patch46: 0046-nft-Reject-tcp-udp-extension-without-proper-protocol.patch -Patch47: 0047-gitignore-Ignore-utils-nfsynproxy.patch -Patch48: 0048-etc-Drop-xtables.conf.patch -Patch49: 0049-Proper-fix-for-unknown-argument-error-message.patch -Patch50: 0050-ebtables-Refuse-unselected-targets-options.patch -Patch51: 0051-extensions-libebt_redirect-Fix-target-translation.patch -Patch52: 0052-extensions-libebt_redirect-Fix-for-wrong-syntax-in-t.patch -Patch53: 0053-extensions-libebt_ip-Do-not-use-ip-dscp-for-translat.patch -Patch54: 0054-extensions-libebt_ip-Translation-has-to-match-on-eth.patch -Patch55: 0055-nft-restore-Fix-for-deletion-of-new-referenced-rule.patch -Patch56: 0056-nft-shared-Drop-unused-include.patch -Patch57: 0057-arptables-Fix-parsing-of-inverted-arp-operation-matc.patch -Patch58: 0058-arptables-Don-t-omit-standard-matches-if-inverted.patch -Patch59: 0059-xshared-Fix-parsing-of-option-arguments-in-same-word.patch +Version: 1.8.11 +Release: 12%{?dist} +Source0: %{url}/files/%{name}-%{version}.tar.xz +source1: %{url}/files/%{name}-%{version}.tar.xz.sig +Source2: coreteam-gpg-key-0xD70D1A666ACF2B21.txt +Source3: iptables.init +Source4: iptables-config +Source5: iptables.service +Source6: sysconfig_iptables +Source7: sysconfig_ip6tables +Source8: arptables-helper +Source9: arptables.service +Source10: ebtables.service +Source11: ebtables-helper +Source12: ebtables-config +# Patch to fix -C handling, already upstream +# https://git.netfilter.org/iptables/patch/?id=40406dbfaefbc204134452b2747bae4f6a122848 +Patch1: iptables-1.8.11-fix-interface-comparisons.patch +# Patch to fix overly strict command option checking +# https://git.netfilter.org/iptables/patch/?id=192c3a6bc18f206895ec5e38812d648ccfe7e281 +Patch2: iptables-1.8.11-command-options-fix.patch # pf.os: ISC license # iptables-apply: Artistic Licence 2.0 -License: GPLv2 and Artistic Licence 2.0 and ISC +License: GPL-2.0-only AND Artistic-2.0 AND ISC # libnetfilter_conntrack is needed for xt_connlabel BuildRequires: pkgconfig(libnetfilter_conntrack) -# libnfnetlink-devel is requires for nfnl_osf +# libnfnetlink-devel is required for nfnl_osf BuildRequires: pkgconfig(libnfnetlink) BuildRequires: libselinux-devel BuildRequires: kernel-headers @@ -96,40 +48,35 @@ BuildRequires: bison BuildRequires: flex BuildRequires: gcc BuildRequires: pkgconfig(libmnl) >= 1.0 -BuildRequires: pkgconfig(libnftnl) >= 1.1.6 +BuildRequires: pkgconfig(libnftnl) >= 1.2.6 # libpcap-devel for nfbpf_compile BuildRequires: libpcap-devel BuildRequires: autoconf BuildRequires: automake BuildRequires: libtool BuildRequires: make +BuildRequires: gnupg2 %description The iptables utility controls the network packet filtering code in the Linux kernel. If you need to set up firewalls and/or IP masquerading, you should install this package. -%package compat -Summary: Temporary transitioning package -Obsoletes: %{name} < 1.8.7-4 -Requires: %{name}-legacy = %{version}-%{release} -Requires: %{name}-utils = %{version}-%{release} - -%description compat -This package only exists to help transition iptables users to the new -package split. It will be removed after one distribution release cycle, please -do not reference it or depend on it in any way. - %package legacy Summary: Legacy tools for managing Linux kernel packet filtering capabilities Requires: %{name}-legacy-libs%{?_isa} = %{version}-%{release} Requires: %{name}-libs%{?_isa} = %{version}-%{release} Conflicts: setup < 2.10.4-1 -Requires(post): %{_sbindir}/update-alternatives -Requires(postun): %{_sbindir}/update-alternatives +Conflicts: alternatives < 1.32-1 +Requires(post): /usr/sbin/update-alternatives +Requires(postun): /usr/sbin/update-alternatives %if 0%{?rhel} < 9 Provides: iptables %endif +Provides: %{name}-compat = %{version}-%{release} +Obsoletes: %{name}-compat < 1.8.9-7 + +%sbin_merge_compat %{_prefix}/sbin/iptables %description legacy The iptables utility controls the network packet filtering code in the @@ -153,9 +100,8 @@ Summary: iptables legacy libraries %description legacy-libs iptables libraries. -Please remember that libip*tc libraries do neither have a stable API nor a real so version. - -For more information about this, please have a look at +Please remember that libip*tc libraries do neither have a stable API nor a real +so version. For more information about this, please have a look at http://www.netfilter.org/documentation/FAQ/netfilter-faq-4.html#ss4.5 @@ -189,6 +135,14 @@ Requires: %{name}-utils = %{version}-%{release} Obsoletes: %{name} < 1.4.16.1 # obsolete ipv6 sub package Obsoletes: %{name}-ipv6 < 1.4.11.1 +# Look at me, I'm the new arptables-services now! +Conflicts: %{name}-nft < 1.8.11-5 +Obsoletes: arptables-services < 0.0.5-16 +Provides: arptables-services = %{version}-%{release} +# Look at me, I'm the new ebtables-services now! +# (With epoch to turn our version number higher value) +Obsoletes: ebtables-services < 2.0.11-20 +Provides: ebtables-services = 1:%{version}-%{release} BuildArch: noarch %description services @@ -211,19 +165,25 @@ a safer way to update iptables remotely. %package nft Summary: nftables compatibility for iptables, arptables and ebtables Requires: %{name}-libs%{?_isa} = %{version}-%{release} -Requires(post): %{_sbindir}/update-alternatives -Requires(post): %{_bindir}/readlink -Requires(postun): %{_sbindir}/update-alternatives +Requires(post): /usr/sbin/update-alternatives +Requires(post): /usr/bin/readlink +Requires(postun): /usr/sbin/update-alternatives Obsoletes: iptables-compat < 1.6.2-4 Provides: arptables-helper Provides: iptables Provides: arptables Provides: ebtables +# allowing old arptables-legacy will break when switching alternatives +# due to the dropped arptables-helper symlink +Conflicts: arptables-legacy < 0.0.5-16 + +%sbin_merge_compat %{_prefix}/sbin/iptables %description nft nftables compatibility for iptables, arptables and ebtables. %prep +%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' %autosetup -p1 %build @@ -246,20 +206,24 @@ rm -f %{buildroot}%{_libdir}/*.la # install init scripts and configuration files install -d -m 755 %{buildroot}%{script_path} -install -c -m 755 %{SOURCE1} %{buildroot}%{script_path}/iptables.init -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE1} > ip6tables.init +install -c -m 755 %{SOURCE3} %{buildroot}%{script_path}/iptables.init +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE3} > ip6tables.init install -c -m 755 ip6tables.init %{buildroot}%{script_path}/ip6tables.init +install -p -m 755 %{SOURCE8} %{SOURCE11} %{buildroot}%{_libexecdir}/ install -d -m 755 %{buildroot}%{_sysconfdir}/sysconfig -install -c -m 600 %{SOURCE2} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config -sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE2} > ip6tables-config +install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables-config +sed -e 's;iptables;ip6tables;g' -e 's;IPTABLES;IP6TABLES;g' < %{SOURCE4} > ip6tables-config install -c -m 600 ip6tables-config %{buildroot}%{_sysconfdir}/sysconfig/ip6tables-config -install -c -m 600 %{SOURCE4} %{buildroot}%{_sysconfdir}/sysconfig/iptables -install -c -m 600 %{SOURCE5} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables +install -c -m 600 %{SOURCE6} %{buildroot}%{_sysconfdir}/sysconfig/iptables +install -c -m 600 %{SOURCE7} %{buildroot}%{_sysconfdir}/sysconfig/ip6tables +echo '# Configure prior to use' > %{buildroot}%{_sysconfdir}/sysconfig/arptables +install -c -m 600 %{SOURCE12} %{buildroot}%{_sysconfdir}/sysconfig/ +touch %{buildroot}%{_sysconfdir}/sysconfig/ebtables # install systemd service files install -d -m 755 %{buildroot}/%{_unitdir} -install -c -m 644 %{SOURCE3} %{buildroot}/%{_unitdir} -sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE3} > ip6tables.service +install -c -m 644 %{SOURCE5} %{SOURCE9} %{SOURCE10} %{buildroot}/%{_unitdir} +sed -e 's;iptables;ip6tables;g' -e 's;IPv4;IPv6;g' -e 's;/usr/libexec/ip6tables;/usr/libexec/iptables;g' < %{SOURCE5} > ip6tables.service install -c -m 644 ip6tables.service %{buildroot}/%{_unitdir} # install legacy actions for service command @@ -285,35 +249,42 @@ install -c -m 755 ip6tabes.panic-legacy %{buildroot}/%{legacy_actions}/ip6tables # Remove /etc/ethertypes (now part of setup) rm -f %{buildroot}%{_sysconfdir}/ethertypes -install -p -D -m 755 %{SOURCE6} %{buildroot}%{_libexecdir}/ -touch %{buildroot}%{_libexecdir}/arptables-helper - # prepare for alternatives touch %{buildroot}%{_mandir}/man8/arptables.8 touch %{buildroot}%{_mandir}/man8/arptables-save.8 touch %{buildroot}%{_mandir}/man8/arptables-restore.8 touch %{buildroot}%{_mandir}/man8/ebtables.8 +rm %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} +touch %{buildroot}%{_sbindir}/{ip,ip6,arp,eb}tables{,-save,-restore} # fix absolute symlink -rm -f %{buildroot}%{_bindir}/iptables-xml -ln -s ../sbin/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml +ln -sf --relative %{buildroot}%{_sbindir}/xtables-legacy-multi %{buildroot}%{_bindir}/iptables-xml %ldconfig_scriptlets %post legacy pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -%{_sbindir}/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --slave $pfx6 ip6tables $pfx6-legacy \ - --slave $pfx-restore iptables-restore $pfx-legacy-restore \ - --slave $pfx-save iptables-save $pfx-legacy-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --slave $pfx6-save ip6tables-save $pfx6-legacy-save + --follower $pfx6 ip6tables $pfx6-legacy \ + --follower $pfx-restore iptables-restore $pfx-legacy-restore \ + --follower $pfx-save iptables-save $pfx-legacy-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --follower $pfx6-save ip6tables-save $pfx6-legacy-save + +%if "%{_sbindir}" == "%{_bindir}" +# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a +# directory. Those symlinks will only be created if there is no symlink +# or file already. +for name in ip{,6}tables{,-save,-restore}; do + test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : +done +%endif %postun legacy if [ $1 -eq 0 ]; then - %{_sbindir}/update-alternatives --remove \ + update-alternatives --remove \ iptables %{_sbindir}/iptables-legacy fi @@ -329,95 +300,112 @@ cp /var/lib/alternatives/iptables /var/tmp/alternatives.iptables.setup %triggerpostun legacy -- iptables > 1.8.0 pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -%{_sbindir}/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-legacy 10 \ - --slave $pfx6 ip6tables $pfx6-legacy \ - --slave $pfx-restore iptables-restore $pfx-legacy-restore \ - --slave $pfx-save iptables-save $pfx-legacy-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ - --slave $pfx6-save ip6tables-save $pfx6-legacy-save + --follower $pfx6 ip6tables $pfx6-legacy \ + --follower $pfx-restore iptables-restore $pfx-legacy-restore \ + --follower $pfx-save iptables-save $pfx-legacy-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-legacy-restore \ + --follower $pfx6-save ip6tables-save $pfx6-legacy-save alternatives --set iptables $(/dev/null || : +done +%endif + %post services +%systemd_post arptables.service ebtables.service %systemd_post iptables.service ip6tables.service %preun services +%systemd_preun arptables.service ebtables.service %systemd_preun iptables.service ip6tables.service %postun services %?ldconfig +%systemd_postun arptables.service ebtables.service %systemd_postun iptables.service ip6tables.service -%post nft +%post -e nft +[[ %%{_excludedocs} == 1 ]] || do_man=true + +# remove non-symlinks in spots managed by alternatives +# to cover for updates from not-yet-alternatived versions +for pfx in %{_prefix}/sbin/{eb,arp}tables; do + for sfx in "" "-restore" "-save"; do + if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then + rm -f $pfx$sfx + fi + done +done +for manpfx in %{_mandir}/man8/{eb,arp}tables; do + for sfx in {,-restore,-save}.8.gz; do + if [ "$(readlink -e $manpfx$sfx)" == $manpfx$sfx ]; then + rm -f $manpfx$sfx + fi + done +done + pfx=%{_sbindir}/iptables pfx6=%{_sbindir}/ip6tables -%{_sbindir}/update-alternatives --install \ +update-alternatives --install \ $pfx iptables $pfx-nft 10 \ - --slave $pfx6 ip6tables $pfx6-nft \ - --slave $pfx-restore iptables-restore $pfx-nft-restore \ - --slave $pfx-save iptables-save $pfx-nft-save \ - --slave $pfx6-restore ip6tables-restore $pfx6-nft-restore \ - --slave $pfx6-save ip6tables-save $pfx6-nft-save + --follower $pfx6 ip6tables $pfx6-nft \ + --follower $pfx-restore iptables-restore $pfx-nft-restore \ + --follower $pfx-save iptables-save $pfx-nft-save \ + --follower $pfx6-restore ip6tables-restore $pfx6-nft-restore \ + --follower $pfx6-save ip6tables-save $pfx6-nft-save pfx=%{_sbindir}/ebtables manpfx=%{_mandir}/man8/ebtables -for sfx in "" "-restore" "-save"; do - if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then - rm -f $pfx$sfx - fi -done -if [ "$(readlink -e $manpfx.8.gz)" == $manpfx.8.gz ]; then - rm -f $manpfx.8.gz -fi -%{_sbindir}/update-alternatives --install \ +update-alternatives --install \ $pfx ebtables $pfx-nft 10 \ - --slave $pfx-save ebtables-save $pfx-nft-save \ - --slave $pfx-restore ebtables-restore $pfx-nft-restore \ - --slave $manpfx.8.gz ebtables-man $manpfx-nft.8.gz + --follower $pfx-save ebtables-save $pfx-nft-save \ + --follower $pfx-restore ebtables-restore $pfx-nft-restore \ + ${do_man:+--follower $manpfx.8.gz ebtables-man $manpfx-nft.8.gz} pfx=%{_sbindir}/arptables manpfx=%{_mandir}/man8/arptables -lepfx=%{_libexecdir}/arptables -for sfx in "" "-restore" "-save"; do - if [ "$(readlink -e $pfx$sfx)" == $pfx$sfx ]; then - rm -f $pfx$sfx - fi - if [ "$(readlink -e $manpfx$sfx.8.gz)" == $manpfx$sfx.8.gz ]; then - rm -f $manpfx$sfx.8.gz - fi -done -if [ "$(readlink -e $lepfx-helper)" == $lepfx-helper ]; then - rm -f $lepfx-helper -fi -%{_sbindir}/update-alternatives --install \ +update-alternatives --install \ $pfx arptables $pfx-nft 10 \ - --slave $pfx-save arptables-save $pfx-nft-save \ - --slave $pfx-restore arptables-restore $pfx-nft-restore \ - --slave $manpfx.8.gz arptables-man $manpfx-nft.8.gz \ - --slave $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz \ - --slave $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz \ - --slave $lepfx-helper arptables-helper $lepfx-nft-helper + --follower $pfx-save arptables-save $pfx-nft-save \ + --follower $pfx-restore arptables-restore $pfx-nft-restore \ + ${do_man:+--follower $manpfx.8.gz arptables-man $manpfx-nft.8.gz} \ + ${do_man:+--follower $manpfx-save.8.gz arptables-save-man $manpfx-nft-save.8.gz} \ + ${do_man:+--follower $manpfx-restore.8.gz arptables-restore-man $manpfx-nft-restore.8.gz} + +%if "%{_sbindir}" == "%{_bindir}" +# Make sure that symlinks in /usr/sbin/ are not missing, if /usr/sbin is a +# directory. Those symlinks will only be created if there is no symlink +# or file already. +for name in ip{,6}tables{,-save,-restore} ebtables{,-save,-restore} arptables{,-save,-restore}; do + test -h /usr/sbin || ln -s ../bin/$name /usr/sbin/$name 2>/dev/null || : +done +%endif %postun nft if [ $1 -eq 0 ]; then for cmd in iptables ebtables arptables; do - %{_sbindir}/update-alternatives --remove \ - $cmd %{_sbindir}/$cmd-nft + update-alternatives --remove $cmd %{_sbindir}/$cmd-nft done fi -%files compat - %files legacy -%doc INCOMPATIBILITIES %{_sbindir}/ip{,6}tables-legacy* %{_sbindir}/xtables-legacy-multi %{_bindir}/iptables-xml %{_mandir}/man1/iptables-xml* %{_mandir}/man8/xtables-legacy* -%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} +%dir %{_datadir}/xtables +%{_datadir}/xtables/iptables.xslt +%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} %files libs %license COPYING @@ -446,9 +434,13 @@ fi %dir %{script_path} %{script_path}/ip{,6}tables.init %config(noreplace) %{_sysconfdir}/sysconfig/ip{,6}tables{,-config} -%{_unitdir}/ip{,6}tables.service +%config(noreplace) %{_sysconfdir}/sysconfig/arptables +%config(noreplace) %{_sysconfdir}/sysconfig/ebtables-config +%ghost %{_sysconfdir}/sysconfig/ebtables +%{_unitdir}/{arp,eb,ip,ip6}tables.service %dir %{legacy_actions}/ip{,6}tables %{legacy_actions}/ip{,6}tables/{save,panic} +%{_libexecdir}/{arp,eb}tables-helper %files utils %license COPYING @@ -467,27 +459,128 @@ fi %{_sbindir}/{eb,arp}tables-nft* %{_sbindir}/xtables-nft-multi %{_sbindir}/xtables-monitor +%{_sbindir}/ebtables-translate +%{_sbindir}/arptables-translate %dir %{_libdir}/xtables %{_libdir}/xtables/lib{arp,eb}t* -%{_libexecdir}/arptables-nft-helper %{_mandir}/man8/xtables-monitor* %{_mandir}/man8/xtables-translate* %{_mandir}/man8/*-nft* %{_mandir}/man8/ip{,6}tables{,-restore}-translate* -%ghost %{_sbindir}/ip{,6}tables{,-save,-restore} -%ghost %{_sbindir}/{eb,arp}tables{,-save,-restore} -%ghost %{_libexecdir}/arptables-helper +%{_mandir}/man8/ebtables-translate* +%{_mandir}/man8/arptables-translate* +%ghost %attr(0755,root,root) %{_sbindir}/ip{,6}tables{,-save,-restore} +%ghost %attr(0755,root,root) %{_sbindir}/{eb,arp}tables{,-save,-restore} %ghost %{_mandir}/man8/arptables{,-save,-restore}.8.gz %ghost %{_mandir}/man8/ebtables.8.gz %changelog -* Wed May 24 2023 Phil Sutter - 1.8.8-5 -- Add fixes from upstream +* Tue Oct 28 2025 Paul Wouters - 1.8.11-12 +- Pull in upstream fix for too strict command option parsing -* Thu Jan 12 2023 Phil Sutter - 1.8.8-4 +* Thu Jul 24 2025 Fedora Release Engineering - 1.8.11-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Tue May 20 2025 Phil Sutter - 1.8.11-10 +- Fix for ghost files not present in iptables-nft RPM + +* Wed May 07 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-9 +- Reapply the change to keep symlinks managed by alternatives under /usr/bin, + this time with a scriptlet create symlinks if /usr/sbin is unmerged. + +* Sat May 03 2025 Phil Sutter - 1.8.11-8 +- Revert last release, it breaks alternatives symlinks + +* Fri Apr 25 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-7 +- Keep symlinks managed by alternatives under /usr/bin + +* Sun Apr 20 2025 Kevin Fenzi - 1.8.11-6 +- Add patch to fix -C handling ( fixes rhbz#2360423 ) + +* Thu Apr 03 2025 Phil Sutter - 1.8.11-5 +- iptables-services to assimilate arptables- and ebtables-services + +* Fri Jan 17 2025 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Tue Jan 14 2025 Zbigniew Jedrzejewski-Szmek - 1.8.11-3 +- Keep symlinks managed by alternatives under /usr/sbin + +* Sun Jan 12 2025 Zbigniew Jędrzejewski-Szmek - 1.8.11-2 +- Rebuilt for the bin-sbin merge (2nd attempt) + +* Fri Nov 08 2024 Phil Sutter - 1.8.11-1 +- new version + +* Thu Jul 18 2024 Fedora Release Engineering - 1.8.10-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Sat Jul 13 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-14 +- Add unmerged-sbin compat also for -legacy subpackage + +* Fri Jul 12 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-13 +- Bump release and add changelog entry + +* Tue Jul 09 2024 Zbigniew Jędrzejewski-Szmek - 1.8.10-12 +- Rebuilt for the bin-sbin merge + +* Fri Jul 05 2024 Phil Sutter - 1.8.10-11 +- Add missing build dependency + +* Fri Jul 05 2024 Phil Sutter - 1.8.10-10 +- Verify tarball GPG signature + +* Wed Jul 03 2024 Phil Sutter - 1.8.10-9 +- Backport fixes from upstream + +* Tue May 21 2024 Phil Sutter - 1.8.10-8 +- Make iptables-legacy own %%{_datadir}/xtables + +* Wed Jan 24 2024 Fedora Release Engineering - 1.8.10-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jan 20 2024 Fedora Release Engineering - 1.8.10-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Thu Jan 11 2024 Phil Sutter - 1.8.10-5 +- Backport fixes from upstream +- Fix flatpak build + +* Tue Nov 07 2023 Phil Sutter - 1.8.10-4 +- The actual obsoletes fix + +* Tue Nov 07 2023 Phil Sutter - 1.8.10-3 +- Fix compat sub-package obsoletion + +* Tue Oct 10 2023 Phil Sutter - 1.8.10-2 +- Obsolete dropped compat package + +* Tue Oct 10 2023 Phil Sutter - 1.8.10-1 +- New version 1.8.10 +- Drop compat sub-package + +* Tue Aug 15 2023 Phil Sutter - 1.8.9-6 +- Convert license to SPDX format + +* Thu Jul 20 2023 Fedora Release Engineering - 1.8.9-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Wed May 24 2023 Phil Sutter - 1.8.9-4 +- Backport fixes from upstream + +* Thu Apr 20 2023 Phil Sutter - 1.8.9-3 +- Support %%_excludedocs macro in alternatives installation + +* Thu Jan 19 2023 Fedora Release Engineering - 1.8.9-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Thu Jan 12 2023 Phil Sutter - 1.8.9-1 - Make iptables-xml a relative symlink -- Add fixes from upstream +- Drop not needed xtables.conf +- Ship iptables.xslt with iptables-legacy package +- Ship ebtables-translate tool with iptables-nft package +- Update to 1.8.9. * Thu Jul 21 2022 Fedora Release Engineering - 1.8.8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild diff --git a/sources b/sources index 014f6c0..1f7b750 100644 --- a/sources +++ b/sources @@ -1 +1,2 @@ -SHA512 (iptables-1.8.8.tar.bz2) = f21df23279a77531a23f3fcb1b8f0f8ec0c726bda236dd0e33af74b06753baff6ce3f26fb9fcceb6fada560656ba901e68fc6452eb840ac1b206bc4654950f59 +SHA512 (iptables-1.8.11.tar.xz) = 4937020bf52d57a45b76e1eba125214a2f4531de52ff1d15185faeef8bea0cd90eb77f99f81baa573944aa122f350a7198cef41d70594e1b65514784addbcc40 +SHA512 (iptables-1.8.11.tar.xz.sig) = 8bde9436b6c6c9d97d9b1cadc417035c209e39b49111ea08fe35b714bbf94721ad0b8b2870791d3bf98154f64912109c6bdeb0ee33f954d0d3a8c3582a97f3f2 diff --git a/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh b/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh index 32eab99..952cd4c 100755 --- a/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh +++ b/tests/RFE-Enable-the-missing-IPv6-SET-target/runtest.sh @@ -29,12 +29,10 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" IPSET=testset6 rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE # rlAssertRpm kernel rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" diff --git a/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh b/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh index 438468d..26a667e 100755 --- a/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh +++ b/tests/RFE-iptables-add-C-option-to-iptables-in-RHEL6/runtest.sh @@ -29,12 +29,10 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" TESTD=$PWD rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "source $TESTD/rules.in" 0 "read ruleset" diff --git a/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh b/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh index 889c1b6..86652af 100755 --- a/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh +++ b/tests/TRACE-target-of-iptables-can-t-work-in/runtest.sh @@ -29,7 +29,6 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" SERVICES="iptables ip6tables firewalld" prepare_page() { @@ -42,7 +41,6 @@ prepare_page() { rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE # rlAssertRpm kernel rlLogInfo $(uname -r) rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" @@ -121,10 +119,14 @@ rlJournalStart rlRun "ip -6 route restore < ip-route.save6" 0 "restore routing info ipv6" rlRun "iptables -t raw -F" rlRun "ip6tables -t raw -F" - rlRun "rmmod nf_log_ipv4" - rlRun "rmmod nf_log_ipv6" - rlRun "rmmod nf_log_common" - rlRun "rmmod nfnetlink_log" 0,1 + if rlTestVersion "$(uname -r)" "<" "4.6"; then + rlRun "rmmod nf_log_ipv4" + rlRun "rmmod nf_log_ipv6" + rlRun "rmmod nf_log_common" + rlRun "rmmod nfnetlink_log" 0,1 + else + rlLogInfo "new kernel detected: skipping unloading modules" + fi rlLogInfo "restoring services" for svc in $SERVICES; do rlServiceRestore $svc diff --git a/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh b/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh index 888dfbd..0b4032e 100755 --- a/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh +++ b/tests/backport-iptables-add-libxt-cgroup-frontend/runtest.sh @@ -29,7 +29,6 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" CGNUM="15" CGNAME="15" CGDIR="/sys/fs/cgroup/net_cls/$CGNAME" @@ -41,7 +40,6 @@ SKIP6=false rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE # rlAssertRpm kernel-$(uname -r) rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" diff --git a/tests/initscript-sanity/runtest.sh b/tests/initscript-sanity/runtest.sh index e270b78..b132033 100755 --- a/tests/initscript-sanity/runtest.sh +++ b/tests/initscript-sanity/runtest.sh @@ -29,11 +29,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlPhaseEnd diff --git a/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh b/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh index 004d568..f68925c 100755 --- a/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh +++ b/tests/ip6tables-do-not-accept-dst-or-src-direction-on-ip6sets/runtest.sh @@ -29,11 +29,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "ip6tables-save > ip6tables.backup" diff --git a/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh b/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh index f59a908..d06fc4a 100755 --- a/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh +++ b/tests/ip6tables-service-does-not-allow-dhcpv6-client-by/runtest.sh @@ -29,11 +29,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "cp /etc/sysconfig/ip6tables ." diff --git a/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh b/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh index 79b2696..2daddb3 100755 --- a/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh +++ b/tests/ip6tables-t-nat-A-POSTROUTING-OUTPUT-with-DROP/runtest.sh @@ -29,12 +29,10 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" SERVICES="iptables ip6tables firewalld" rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" for svc in $SERVICES; do diff --git a/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh b/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh index d17e693..f409501 100755 --- a/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh +++ b/tests/iptables-rule-deletion-fails-for-rules-that-use/runtest.sh @@ -29,13 +29,11 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" IPSET4="ipsetv4" IPSET6="ipsetv6" rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlRun "ipset create $IPSET4 hash:ip" diff --git a/tests/iptables-save-cuts-space-before-j/runtest.sh b/tests/iptables-save-cuts-space-before-j/runtest.sh index a6a5099..bba6bf2 100755 --- a/tests/iptables-save-cuts-space-before-j/runtest.sh +++ b/tests/iptables-save-cuts-space-before-j/runtest.sh @@ -29,11 +29,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlServiceStart iptables diff --git a/tests/iptables-save-modprobe-option/runtest.sh b/tests/iptables-save-modprobe-option/runtest.sh index 22951c4..240c76e 100755 --- a/tests/iptables-save-modprobe-option/runtest.sh +++ b/tests/iptables-save-modprobe-option/runtest.sh @@ -30,11 +30,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartTest - rlAssertRpm $PACKAGE rlRun "iptables-save -M /dev/null" 0 "iptables-save -M ... supported" rlRun "iptables-save --modprobe /dev/null" 0 "iptables-save --modprobe ... supported" rlPhaseEnd diff --git a/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh b/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh index c3223b5..abfb03a 100755 --- a/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh +++ b/tests/xtables-tools-locking-vulnerable-to-local-DoS/runtest.sh @@ -29,11 +29,8 @@ . /usr/bin/rhts-environment.sh || exit 1 . /usr/share/beakerlib/beakerlib.sh || exit 1 -PACKAGE="iptables" - rlJournalStart rlPhaseStartSetup - rlAssertRpm $PACKAGE rlRun "TmpDir=\$(mktemp -d)" 0 "Creating tmp directory" rlRun "pushd $TmpDir" rlPhaseEnd