2024-02-24 12:13:50

by Arnd Bergmann

[permalink] [raw]
Subject: [PATCH] netfilter: xtables: fix IP6_NF_IPTABLES_LEGACY typo

From: Arnd Bergmann <[email protected]>

CONFIG_IP_NF_NAT accidentally selects the wrong NF_IPTABLES_LEGACY
symbol, which ends up causing a link failure in some configurations:

WARNING: unmet direct dependencies detected for IP6_NF_IPTABLES_LEGACY
Depends on [n]: NET [=y] && INET [=y] && IPV6 [=n] && NETFILTER [=y]
Selected by [m]:

Select IP_NF_IPTABLES_LEGACY instead of IP6_NF_IPTABLES_LEGACY.

Fixes: a9525c7f6219 ("netfilter: xtables: allow xtables-nft only builds")
Signed-off-by: Arnd Bergmann <[email protected]>
---
net/ipv4/netfilter/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv4/netfilter/Kconfig b/net/ipv4/netfilter/Kconfig
index 87d890172809..8f6e950163a7 100644
--- a/net/ipv4/netfilter/Kconfig
+++ b/net/ipv4/netfilter/Kconfig
@@ -217,7 +217,7 @@ config IP_NF_NAT
default m if NETFILTER_ADVANCED=n
select NF_NAT
select NETFILTER_XT_NAT
- select IP6_NF_IPTABLES_LEGACY
+ select IP_NF_IPTABLES_LEGACY
help
This enables the `nat' table in iptables. This allows masquerading,
port forwarding and other forms of full Network Address Port
--
2.39.2



2024-02-24 13:23:48

by Florian Westphal

[permalink] [raw]
Subject: Re: [PATCH] netfilter: xtables: fix IP6_NF_IPTABLES_LEGACY typo

Arnd Bergmann <[email protected]> wrote:
> From: Arnd Bergmann <[email protected]>
>
> CONFIG_IP_NF_NAT accidentally selects the wrong NF_IPTABLES_LEGACY
> symbol, which ends up causing a link failure in some configurations:
>
> WARNING: unmet direct dependencies detected for IP6_NF_IPTABLES_LEGACY
> Depends on [n]: NET [=y] && INET [=y] && IPV6 [=n] && NETFILTER [=y]
> Selected by [m]:
>
> Select IP_NF_IPTABLES_LEGACY instead of IP6_NF_IPTABLES_LEGACY.

Patch is correct but this is already fixed via
749d4ef0868c ("netfilter: xtables: fix up kconfig dependencies")