netfilter: nf_nat: handle NF_DROP from nfnetlink_parse_nat_setup()
authorPablo Neira Ayuso <pablo@netfilter.org>
Fri, 9 Sep 2016 13:38:12 +0000 (15:38 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 12 Sep 2016 18:32:57 +0000 (20:32 +0200)
commitecfcdfec7e0cc64215a194044305f02a5a836e6d
tree955326d1fee680de672f6bb320bb418d56a83c96
parentd1a6cba576fc7c43e476538fe5aa72fe04bd80e1
netfilter: nf_nat: handle NF_DROP from nfnetlink_parse_nat_setup()

nf_nat_setup_info() returns NF_* verdicts, so convert them to error
codes that is what ctnelink expects. This has passed overlook without
having any impact since this nf_nat_setup_info() has always returned
NF_ACCEPT so far. Since 870190a9ec90 ("netfilter: nat: convert nat bysrc
hash to rhashtable"), this is problem.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_nat_core.c