• Pablo Neira Ayuso's avatar
    netfilter: nf_tables: fix trace of matching non-terminal rule · 3b084e99
    Pablo Neira Ayuso authored
    Add the corresponding trace if we have a full match in a non-terminal
    rule. Note that the traces will look slightly different than in
    x_tables since the log message after all expressions have been
    evaluated (contrary to x_tables, that emits it before the target
    action). This manifests in two differences in nf_tables wrt. x_tables:
    
    1) The rule that enables the tracing is included in the trace.
    
    2) If the rule emits some log message, that is shown before the
       trace log message.
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    3b084e99
nf_tables_core.c 6.42 KB