aboutsummaryrefslogtreecommitdiffstats
path: root/net/ipv6/netfilter/ip6table_raw.c
diff options
context:
space:
mode:
authorJan Engelhardt <jengelh@medozas.de>2009-07-18 15:22:30 +0200
committerJan Engelhardt <jengelh@medozas.de>2009-08-10 13:35:31 +0200
commite2fe35c17fed62d4ab5038fa9bc489e967ff8416 (patch)
tree84a4b0b688276b6788081f441984abd01d036b4d /net/ipv6/netfilter/ip6table_raw.c
parentnetfilter: xtables: check for unconditionality of policies (diff)
downloadlinux-dev-e2fe35c17fed62d4ab5038fa9bc489e967ff8416.tar.xz
linux-dev-e2fe35c17fed62d4ab5038fa9bc489e967ff8416.zip
netfilter: xtables: check for standard verdicts in policies
This adds the second check that Rusty wanted to have a long time ago. :-) Base chain policies must have absolute verdicts that cease processing in the table, otherwise rule execution may continue in an unexpected spurious fashion (e.g. next chain that follows in memory). Signed-off-by: Jan Engelhardt <jengelh@medozas.de>
Diffstat (limited to 'net/ipv6/netfilter/ip6table_raw.c')
0 files changed, 0 insertions, 0 deletions