Re: [PATCH nf] netfilter: Support expectations in different zones

2015-07-22 Thread Pablo Neira Ayuso
On Tue, Jul 21, 2015 at 09:37:31PM -0700, Joe Stringer wrote: When zones were originally introduced, the expectation functions were all extended to perform lookup using the zone. However, insertion was not modified to check the zone. This means that two expectations which are intended to apply

[PATCH nf] netfilter: Support expectations in different zones

2015-07-21 Thread Joe Stringer
When zones were originally introduced, the expectation functions were all extended to perform lookup using the zone. However, insertion was not modified to check the zone. This means that two expectations which are intended to apply for different connections that have the same tuple but exist in