Files
twx-linux/net
Henry Yen 73aa8292ca netfilter: nft_flow_offload: fix checking method of conntrack helper
[ Upstream commit 2314e87974 ]

This patch uses nfct_help() to detect whether an established connection
needs conntrack helper instead of using test_bit(IPS_HELPER_BIT,
&ct->status).

The reason is that IPS_HELPER_BIT is only set when using explicit CT
target.

However, in the case that a device enables conntrack helper via command
"echo 1 > /proc/sys/net/netfilter/nf_conntrack_helper", the status of
IPS_HELPER_BIT will not present any change, and consequently it loses
the checking ability in the context.

Signed-off-by: Henry Yen <henry.yen@mediatek.com>
Reviewed-by: Ryder Lee <ryder.lee@mediatek.com>
Tested-by: John Crispin <john@phrozen.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2019-02-27 10:08:55 +01:00
..
2019-01-13 09:51:08 +01:00
2019-02-23 09:07:27 +01:00
2019-01-31 08:14:31 +01:00
2019-02-06 17:30:07 +01:00
2019-02-12 19:47:22 +01:00
2019-01-13 09:51:00 +01:00