netfilter: xt_conntrack: fix inverted conntrack direction test
authorFlorian Westphal <fw@strlen.de>
Mon, 4 Apr 2011 15:06:21 +0000 (17:06 +0200)
committerPatrick McHardy <kaber@trash.net>
Mon, 4 Apr 2011 15:06:21 +0000 (17:06 +0200)
--ctdir ORIGINAL matches REPLY packets, and vv:

userspace sets "invert_flags &= ~XT_CONNTRACK_DIRECTION" in ORIGINAL
case.

Thus: (CTINFO2DIR(ctinfo) == IP_CT_DIR_ORIGINAL) ^
      !!(info->invert_flags & XT_CONNTRACK_DIRECTION))

yields "1 ^ 0", which is true -> returns false.

Reproducer:
iptables -I OUTPUT 1 -p tcp --syn -m conntrack --ctdir ORIGINAL

Signed-off-by: Florian Westphal <fwestphal@astaro.com>
Signed-off-by: Patrick McHardy <kaber@trash.net>

No differences found