[Devel] [PATCH] netfilter: Add {ipt,ip6t}_osf aliases for xt_osf

Kirill Tkhai ktkhai at odin.com
Wed Jun 3 09:33:33 PDT 2015

Porting mainstream commit b8ddd9eac8788b0aa9a9d4e09d76dc9e1667bb2c:

    Orig author: Kirill Tkhai <ktkhai at parallels.com>

    netfilter: Add {ipt,ip6t}_osf aliases for xt_osf

    There are no these aliases, so kernel can not request appropriate
    match table:

    $ iptables -I INPUT -p tcp -m osf --genre Windows --ttl 2 -j DROP
    iptables: No chain/target/match by that name.

    setsockopt() requests ipt_osf module, which is not present. Add
    the aliases.

    Signed-off-by: Kirill Tkhai <ktkhai at parallels.com>
    Signed-off-by: Pablo Neira Ayuso <pablo at netfilter.org>

Signed-off-by: Kirill Tkhai <ktkhai at odin.com>
 net/netfilter/xt_osf.c |    2 ++
 1 file changed, 2 insertions(+)

diff --git a/net/netfilter/xt_osf.c b/net/netfilter/xt_osf.c
index 647d989..3b6522b 100644
--- a/net/netfilter/xt_osf.c
+++ b/net/netfilter/xt_osf.c
@@ -422,5 +422,7 @@ module_exit(xt_osf_fini);
 MODULE_AUTHOR("Evgeniy Polyakov <zbr at ioremap.net>");
 MODULE_DESCRIPTION("Passive OS fingerprint matching.");

More information about the Devel mailing list