Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-08 Thread Phil Sutter
On Wed, Mar 08, 2017 at 02:38:42PM +0100, Pablo Neira Ayuso wrote: > On Wed, Mar 08, 2017 at 01:31:51PM +0100, Phil Sutter wrote: > > On Wed, Mar 08, 2017 at 11:36:52AM +0100, Pablo Neira Ayuso wrote: > > > On Tue, Mar 07, 2017 at 09:07:45PM +0100, Phil Sutter wrote: > > > > On Tue, Mar 07, 2017

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-08 Thread Phil Sutter
On Wed, Mar 08, 2017 at 01:31:51PM +0100, Phil Sutter wrote: > Oh man, I just found the cause: I was running iptables-translate as > unprivileged user. Calling it with sudo magically makes everything work. > > I'll have a look whether it's possible to communicate the received > -EPERM back to the

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-08 Thread Phil Sutter
On Wed, Mar 08, 2017 at 11:36:52AM +0100, Pablo Neira Ayuso wrote: > On Tue, Mar 07, 2017 at 09:07:45PM +0100, Phil Sutter wrote: > > On Tue, Mar 07, 2017 at 08:31:58PM +0100, Pablo Neira Ayuso wrote: > > > On Tue, Mar 07, 2017 at 05:54:09PM +0100, Phil Sutter wrote: > > > > On Tue, Mar 07, 2017

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-08 Thread Pablo Neira Ayuso
On Tue, Mar 07, 2017 at 09:07:45PM +0100, Phil Sutter wrote: > On Tue, Mar 07, 2017 at 08:31:58PM +0100, Pablo Neira Ayuso wrote: > > On Tue, Mar 07, 2017 at 05:54:09PM +0100, Phil Sutter wrote: > > > On Tue, Mar 07, 2017 at 05:20:55PM +0100, Pablo Neira Ayuso wrote: > > > > On Tue, Mar 07, 2017

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-07 Thread Pablo Neira Ayuso
On Tue, Mar 07, 2017 at 05:54:09PM +0100, Phil Sutter wrote: > On Tue, Mar 07, 2017 at 05:20:55PM +0100, Pablo Neira Ayuso wrote: > > On Tue, Mar 07, 2017 at 05:17:29PM +0100, Pablo Neira Ayuso wrote: > > > On Tue, Mar 07, 2017 at 04:35:07PM +0100, Phil Sutter wrote: > > > > While translating a

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-07 Thread Phil Sutter
On Tue, Mar 07, 2017 at 08:31:58PM +0100, Pablo Neira Ayuso wrote: > On Tue, Mar 07, 2017 at 05:54:09PM +0100, Phil Sutter wrote: > > On Tue, Mar 07, 2017 at 05:20:55PM +0100, Pablo Neira Ayuso wrote: > > > On Tue, Mar 07, 2017 at 05:17:29PM +0100, Pablo Neira Ayuso wrote: > > > > On Tue, Mar 07,

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-07 Thread Phil Sutter
On Tue, Mar 07, 2017 at 05:20:55PM +0100, Pablo Neira Ayuso wrote: > On Tue, Mar 07, 2017 at 05:17:29PM +0100, Pablo Neira Ayuso wrote: > > On Tue, Mar 07, 2017 at 04:35:07PM +0100, Phil Sutter wrote: > > > While translating a conntrack state match in old syntax, matches are > > > looked up by

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-07 Thread Pablo Neira Ayuso
On Tue, Mar 07, 2017 at 04:35:07PM +0100, Phil Sutter wrote: > While translating a conntrack state match in old syntax, matches are > looked up by name, only. This returned the revision 0 entry since > matches are registered in reverse order of appearance in the array > passed to

Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft

2017-03-07 Thread Pablo Neira Ayuso
On Tue, Mar 07, 2017 at 05:17:29PM +0100, Pablo Neira Ayuso wrote: > On Tue, Mar 07, 2017 at 04:35:07PM +0100, Phil Sutter wrote: > > While translating a conntrack state match in old syntax, matches are > > looked up by name, only. This returned the revision 0 entry since > > matches are