]> www.infradead.org Git - users/willy/xarray.git/commit
openvswitch: prepare for stolen verdict coming from conntrack and nat engine
authorFlorian Westphal <fw@strlen.de>
Wed, 3 Jul 2024 10:46:34 +0000 (12:46 +0200)
committerDavid S. Miller <davem@davemloft.net>
Fri, 5 Jul 2024 10:05:05 +0000 (11:05 +0100)
commitc7f79f2620b7776586c626edf21eb6ed6ed3d1eb
tree2f38034c6813084001e57e39b13f408917d5e19b
parentaba43bdfdccf15da1dfdc657bd9dada9010d77a4
openvswitch: prepare for stolen verdict coming from conntrack and nat engine

At this time, conntrack either returns NF_ACCEPT or NF_DROP.
To improve debuging it would be nice to be able to replace NF_DROP
verdict with NF_DROP_REASON() helper,

This helper releases the skb instantly (so drop_monitor can pinpoint
precise location) and returns NF_STOLEN.

Prepare call sites to deal with this before introducing such changes
in conntrack and nat core.

Signed-off-by: Florian Westphal <fw@strlen.de>
Reviewed-by: Aaron Conole <aconole@redhat.om>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/openvswitch/conntrack.c