]> git.proxmox.com Git - mirror_ubuntu-focal-kernel.git/commit
netfilter: nft_reject_bridge: enable reject with bridge vlan
authorMichael Braun <michael-dev@fami-braun.de>
Wed, 6 May 2020 09:46:25 +0000 (11:46 +0200)
committerMarcelo Henrique Cerri <marcelo.cerri@canonical.com>
Mon, 22 Jun 2020 20:23:39 +0000 (17:23 -0300)
commit19933b0d545e0ad901cb8c589aa89d70be1fe70a
treed5d9923e4958ad043712d86247de9b3390e84365
parent352f43c8e968c0a32161adbc1c16b062421fbd69
netfilter: nft_reject_bridge: enable reject with bridge vlan

BugLink: https://bugs.launchpad.net/bugs/1881927
commit e9c284ec4b41c827f4369973d2792992849e4fa5 upstream.

Currently, using the bridge reject target with tagged packets
results in untagged packets being sent back.

Fix this by mirroring the vlan id as well.

Fixes: 85f5b3086a04 ("netfilter: bridge: add reject support")
Signed-off-by: Michael Braun <michael-dev@fami-braun.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
Signed-off-by: Khalid Elmously <khalid.elmously@canonical.com>
net/bridge/netfilter/nft_reject_bridge.c