Commit 1cc34c30 authored by Richard Weinberger's avatar Richard Weinberger Committed by Jan Engelhardt

netfilter: xt_connlimit: use hotdrop jump mark

Signed-off-by: default avatarRichard Weinberger <richard@nod.at>
Signed-off-by: default avatarJan Engelhardt <jengelh@medozas.de>
parent ae9d67af
......@@ -204,11 +204,9 @@ connlimit_mt(const struct sk_buff *skb, struct xt_action_param *par)
&info->mask, par->family);
spin_unlock_bh(&info->data->lock);
if (connections < 0) {
if (connections < 0)
/* kmalloc failed, drop it entirely */
par->hotdrop = true;
return false;
}
goto hotdrop;
return (connections > info->limit) ^ info->inverse;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment