提交 5ca431f9 编写于 作者: E Eric Leblond 提交者: Patrick McHardy

netfilter: nfnetlink_log: fix per-rule qthreshold override

In NFLOG the per-rule qthreshold should overrides per-instance only
it is set. With current code, the per-rule qthreshold is 1 if not set
and it overrides the per-instance qthreshold.

This patch modifies the default xt_NFLOG threshold from 1 to
0. Thus a value of 0 means there is no per-rule setting and the instance
parameter has to apply.
Signed-off-by: NEric Leblond <eric@inl.fr>
Signed-off-by: NPatrick McHardy <kaber@trash.net>
上级 4aa3b2ee
...@@ -2,7 +2,7 @@ ...@@ -2,7 +2,7 @@
#define _XT_NFLOG_TARGET #define _XT_NFLOG_TARGET
#define XT_NFLOG_DEFAULT_GROUP 0x1 #define XT_NFLOG_DEFAULT_GROUP 0x1
#define XT_NFLOG_DEFAULT_THRESHOLD 1 #define XT_NFLOG_DEFAULT_THRESHOLD 0
#define XT_NFLOG_MASK 0x0 #define XT_NFLOG_MASK 0x0
......
...@@ -590,8 +590,10 @@ nfulnl_log_packet(u_int8_t pf, ...@@ -590,8 +590,10 @@ nfulnl_log_packet(u_int8_t pf,
qthreshold = inst->qthreshold; qthreshold = inst->qthreshold;
/* per-rule qthreshold overrides per-instance */ /* per-rule qthreshold overrides per-instance */
if (qthreshold > li->u.ulog.qthreshold) if (li->u.ulog.qthreshold)
qthreshold = li->u.ulog.qthreshold; if (qthreshold > li->u.ulog.qthreshold)
qthreshold = li->u.ulog.qthreshold;
switch (inst->copy_mode) { switch (inst->copy_mode) {
case NFULNL_COPY_META: case NFULNL_COPY_META:
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册