netfilter: nf_ct_ipv4: handle invalid IPv4 and IPv6 packets consistently
authorJozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Mon, 9 Apr 2012 14:32:16 +0000 (16:32 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 9 Apr 2012 22:38:34 +0000 (00:38 +0200)
commit8430eac2f6a3c2adce22d490e2ab8bb50d59077a
tree0513c19811d4a34a122155351ee5728572ddadaf
parent95ad2f873d5d404dc9ebc2377de0b762346346c0
netfilter: nf_ct_ipv4: handle invalid IPv4 and IPv6 packets consistently

IPv6 conntrack marked invalid packets as INVALID and let the user
drop those by an explicit rule, while IPv4 conntrack dropped such
packets itself.

IPv4 conntrack is changed so that it marks INVALID packets and let
the user to drop them.

Signed-off-by: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c