Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1249137 > unrolled thread

[PATCH] netfilter: fix Kconfig dependencies for nft_dup_ipv{4,6}

Started byArnd Bergmann <arnd@arndb.de>
First post2015-10-16 22:20 +0200
Last post2015-10-17 13:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] netfilter: fix Kconfig dependencies for nft_dup_ipv{4,6} Arnd Bergmann <arnd@arndb.de> - 2015-10-16 22:20 +0200
    Re: [PATCH] netfilter: fix Kconfig dependencies for nft_dup_ipv{4,6} Pablo Neira Ayuso <pablo@netfilter.org> - 2015-10-17 13:30 +0200

#1249137 — [PATCH] netfilter: fix Kconfig dependencies for nft_dup_ipv{4,6}

FromArnd Bergmann <arnd@arndb.de>
Date2015-10-16 22:20 +0200
Subject[PATCH] netfilter: fix Kconfig dependencies for nft_dup_ipv{4,6}
Message-ID<qkjDQ-ax-17@gated-at.bofh.it>
nft_dup_ipv4 and nft_dup_ipv6 select the respective nf_dup_ipv{4,6}
drivers, which must not be built-in if nf_conntrack is a loadable
module, otherwise we get a link error:

net/built-in.o: In function `nf_dup_ipv6':
(.text+0xdef20): undefined reference to `nf_conntrack_untracked'

The dependency was fixed for the nf_dup_* modules recently, but this
patch adds the same dependency to the nft_dup_* modules for
the (hopefully) complete fix.

Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Fixes: 6ece90f9a13e ("netfilter: fix Kconfig dependencies for nf_dup_ipv{4,6}")
---
found on ARM randconfig builds

diff --git a/net/ipv4/netfilter/Kconfig b/net/ipv4/netfilter/Kconfig
index a35584176535..c187c60e3e0c 100644
--- a/net/ipv4/netfilter/Kconfig
+++ b/net/ipv4/netfilter/Kconfig
@@ -60,6 +60,7 @@ config NFT_REJECT_IPV4
 
 config NFT_DUP_IPV4
 	tristate "IPv4 nf_tables packet duplication support"
+	depends on !NF_CONNTRACK || NF_CONNTRACK
 	select NF_DUP_IPV4
 	help
 	  This module enables IPv4 packet duplication support for nf_tables.
diff --git a/net/ipv6/netfilter/Kconfig b/net/ipv6/netfilter/Kconfig
index f6a024e141e5..e10a04c9cdc7 100644
--- a/net/ipv6/netfilter/Kconfig
+++ b/net/ipv6/netfilter/Kconfig
@@ -49,6 +49,7 @@ config NFT_REJECT_IPV6
 
 config NFT_DUP_IPV6
 	tristate "IPv6 nf_tables packet duplication support"
+	depends on !NF_CONNTRACK || NF_CONNTRACK
 	select NF_DUP_IPV6
 	help
 	  This module enables IPv6 packet duplication support for nf_tables.

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1249312

FromPablo Neira Ayuso <pablo@netfilter.org>
Date2015-10-17 13:30 +0200
Message-ID<qkxQt-4hC-7@gated-at.bofh.it>
In reply to#1249137
On Fri, Oct 16, 2015 at 10:10:04PM +0200, Arnd Bergmann wrote:
> nft_dup_ipv4 and nft_dup_ipv6 select the respective nf_dup_ipv{4,6}
> drivers, which must not be built-in if nf_conntrack is a loadable
> module, otherwise we get a link error:
> 
> net/built-in.o: In function `nf_dup_ipv6':
> (.text+0xdef20): undefined reference to `nf_conntrack_untracked'
> 
> The dependency was fixed for the nf_dup_* modules recently, but this
> patch adds the same dependency to the nft_dup_* modules for
> the (hopefully) complete fix.

Already have this patch for this enqueued here:

http://git.kernel.org/cgit/linux/kernel/git/pablo/nf.git/commit/?id=6ece90f9a13e2592cbd6634f74bcb306169b5ab6

Will be submitting this to David asap. Thanks anyway.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web