Bug 1804726 - RFE: Complete among match support in ebtables-nft
Summary: RFE: Complete among match support in ebtables-nft
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: iptables
Version: 8.3
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: rc
: 8.3
Assignee: Phil Sutter
QA Contact: Tomas Dolezal
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-02-19 14:13 UTC by Phil Sutter
Modified: 2020-11-04 01:55 UTC (History)
2 users (show)

Fixed In Version: iptables-1.8.4-11.el8
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-11-04 01:54:58 UTC
Type: Feature Request
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:4518 0 None None None 2020-11-04 01:55:11 UTC

Internal Links: 1877022

Description Phil Sutter 2020-02-19 14:13:46 UTC
Upstream recently received full among match support by making use of concatenated ranges support in nftables:

commit c33bae9c6c7a49c8af16df846e6112fc4727e643
Author: Phil Sutter <phil@nwl.cc>
Date:   Thu Feb 13 17:49:53 2020 +0100

    ebtables: among: Support mixed MAC and MAC/IP entries
    
    Powered by Stefano's support for concatenated ranges, a full among match
    replacement can be implemented. The trick is to add MAC-only elements as
    a concatenation of MAC and zero-length prefix, i.e. a range from
    0.0.0.0 till 255.255.255.255.
    
    Although not quite needed, detection of pure MAC-only matches is left in
    place. For those, no implicit 'meta protocol' match is added (which is
    required otherwise at least to keep nft output correct) and no concat
    type is used for the set.
    
    Signed-off-by: Phil Sutter <phil@nwl.cc>

Comment 7 errata-xmlrpc 2020-11-04 01:54:58 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (iptables bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:4518


Note You need to log in before you can comment on or make changes to this bug.