Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-5825

ebtables-nft eats '-p LENGTH' parameter

    • iptables-1.8.10-2.el9
    • None
    • Moderate
    • TestOnly
    • rhel-sst-networking-core
    • ssg_networking
    • 4
    • Dev ack
    • False
    • No
    • None
    • Requested
    • None
    • If docs needed, set a value
    • None

      If users specify the special protocol name "LENGTH", Ethernet frames which use the etherproto field as length value should match (basically all etherproto field values less than 0x0600, or 1536 in decimal).

      ebtables-nft does accept the special name, but the flag it sets is not effective.

      In RHEL9, situation is even worse due to accidental flag value misinterpretation: Any '-p' value should be ignored and instead verbose mode is enabled. This problem is consistent with upstream.

              psutter@redhat.com Phil Sutter
              psutter@redhat.com Phil Sutter
              Phil Sutter Phil Sutter
              Tomas Dolezal Tomas Dolezal
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: