netfilter: flowtable infrastructure depends on NETFILTER_INGRESS

"Linux Kernel Mailing List" <[email protected]>
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/6be3bcd75afb673a37a82e18ba46d50430f172c1
Commit:     6be3bcd75afb673a37a82e18ba46d50430f172c1
Parent:     ea23d5e3bf340e413b8e05c13da233c99c64142b
Refname:    refs/heads/master
Author:     Pablo Neira Ayuso <[email protected]>
AuthorDate: Wed Jan 31 18:13:39 2018 +0100
Committer:  Pablo Neira Ayuso <[email protected]>
CommitDate: Fri Feb 2 13:21:48 2018 +0100

    netfilter: flowtable infrastructure depends on NETFILTER_INGRESS
    
    config NF_FLOW_TABLE depends on NETFILTER_INGRESS. If users forget to
    enable this toggle, flowtable registration fails with EOPNOTSUPP.
    
    Moreover, turn 'select NF_FLOW_TABLE' in every flowtable family flavour
    into dependency instead, otherwise this new dependency on
    NETFILTER_INGRESS causes a warning. This also allows us to remove the
    explicit dependency between family flowtables <-> NF_TABLES and
    NF_CONNTRACK, given they depend on the NF_FLOW_TABLE core that already
    expresses the general dependencies for this new infrastructure.
    
    Moreover, NF_FLOW_TABLE_INET depends on NF_FLOW_TABLE_IPV4 and
    NF_FLOWTABLE_IPV6, which already depends on NF_FLOW_TABLE. So we can get
    rid of direct dependency with NF_FLOW_TABLE.
    
    In general, let's avoid 'select', it just makes things more complicated.
    
    Reported-by: John Crispin <[email protected]>
    Signed-off-by: Pablo Neira Ayuso <[email protected]>
---
 net/ipv4/netfilter/Kconfig | 3 +--
 net/ipv6/netfilter/Kconfig | 3 +--
 net/netfilter/Kconfig      | 8 +++++---
 3 files changed, 7 insertions(+), 7 deletions(-)

diff --git a/net/ipv4/netfilter/Kconfig b/net/ipv4/netfilter/Kconfig
index 5f52236780b4..dfe6fa4ea554 100644
--- a/net/ipv4/netfilter/Kconfig
+++ b/net/ipv4/netfilter/Kconfig
@@ -80,8 +80,7 @@ endif # NF_TABLES
 
 config NF_FLOW_TABLE_IPV4
 	tristate "Netfilter flow table IPv4 module"
-	depends on NF_CONNTRACK && NF_TABLES
-	select NF_FLOW_TABLE
+	depends on NF_FLOW_TABLE
 	help
 	  This option adds the flow table IPv4 support.
 
diff --git a/net/ipv6/netfilter/Kconfig b/net/ipv6/netfilter/Kconfig
index 4a634b7a2c80..d395d1590699 100644
--- a/net/ipv6/netfilter/Kconfig
+++ b/net/ipv6/netfilter/Kconfig
@@ -73,8 +73,7 @@ endif # NF_TABLES
 
 config NF_FLOW_TABLE_IPV6
 	tristate "Netfilter flow table IPv6 module"
-	depends on NF_CONNTRACK && NF_TABLES
-	select NF_FLOW_TABLE
+	depends on NF_FLOW_TABLE
 	help
 	  This option adds the flow table IPv6 support.
 
diff --git a/net/netfilter/Kconfig b/net/netfilter/Kconfig
index 9019fa98003d..d3220b43c832 100644
--- a/net/netfilter/Kconfig
+++ b/net/netfilter/Kconfig
@@ -666,8 +666,8 @@ endif # NF_TABLES
 
 config NF_FLOW_TABLE_INET
 	tristate "Netfilter flow table mixed IPv4/IPv6 module"
-	depends on NF_FLOW_TABLE_IPV4 && NF_FLOW_TABLE_IPV6
-	select NF_FLOW_TABLE
+	depends on NF_FLOW_TABLE_IPV4
+	depends on NF_FLOW_TABLE_IPV6
 	help
           This option adds the flow table mixed IPv4/IPv6 support.
 
@@ -675,7 +675,9 @@ config NF_FLOW_TABLE_INET
 
 config NF_FLOW_TABLE
 	tristate "Netfilter flow table module"
-	depends on NF_CONNTRACK && NF_TABLES
+	depends on NETFILTER_INGRESS
+	depends on NF_CONNTRACK
+	depends on NF_TABLES
 	help
 	  This option adds the flow table core infrastructure.
 
--
To unsubscribe from this list: send the line "unsubscribe git-commits-head" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.