• Arnd Bergmann's avatar
    netfilter: improve flow table Kconfig dependencies · a0a97f2a
    Arnd Bergmann authored
    The newly added NF_FLOW_TABLE options cause some build failures in
    randconfig kernels:
    
    - when CONFIG_NF_CONNTRACK is disabled, or is a loadable module but
      NF_FLOW_TABLE is built-in:
    
      In file included from net/netfilter/nf_flow_table.c:8:0:
      include/net/netfilter/nf_conntrack.h:59:22: error: field 'ct_general' has incomplete type
        struct nf_conntrack ct_general;
      include/net/netfilter/nf_conntrack.h: In function 'nf_ct_get':
      include/net/netfilter/nf_conntrack.h:148:15: error: 'const struct sk_buff' has no member named '_nfct'
      include/net/netfilter/nf_conntrack.h: In function 'nf_ct_put':
      include/net/netfilter/nf_conntrack.h:157:2: error: implicit declaration of function 'nf_conntrack_put'; did you mean 'nf_ct_put'? [-Werror=implicit-function-declaration]
    
      net/netfilter/nf_flow_table.o: In function `nf_flow_offload_work_gc':
      (.text+0x1540): undefined reference to `nf_ct_delete'
    
    - when CONFIG_NF_TABLES is disabled:
    
      In file included from net/ipv6/netfilter/nf_flow_table_ipv6.c:13:0:
      include/net/netfilter/nf_tables.h: In function 'nft_gencursor_next':
      include/net/netfilter/nf_tables.h:1189:14: error: 'const struct net' has no member named 'nft'; did you mean 'nf'?
    
     - when CONFIG_NF_FLOW_TABLE_INET is enabled, but NF_FLOW_TABLE_IPV4
      or NF_FLOW_TABLE_IPV6 are not, or are loadable modules
    
      net/netfilter/nf_flow_table_inet.o: In function `nf_flow_offload_inet_hook':
      nf_flow_table_inet.c:(.text+0x94): undefined reference to `nf_flow_offload_ipv6_hook'
      nf_flow_table_inet.c:(.text+0x40): undefined reference to `nf_flow_offload_ip_hook'
    
    - when CONFIG_NF_FLOW_TABLES is disabled, but the other options are
      enabled:
    
      net/netfilter/nf_flow_table_inet.o: In function `nf_flow_offload_inet_hook':
      nf_flow_table_inet.c:(.text+0x6c): undefined reference to `nf_flow_offload_ipv6_hook'
      net/netfilter/nf_flow_table_inet.o: In function `nf_flow_inet_module_exit':
      nf_flow_table_inet.c:(.exit.text+0x8): undefined reference to `nft_unregister_flowtable_type'
      net/netfilter/nf_flow_table_inet.o: In function `nf_flow_inet_module_init':
      nf_flow_table_inet.c:(.init.text+0x8): undefined reference to `nft_register_flowtable_type'
      net/ipv4/netfilter/nf_flow_table_ipv4.o: In function `nf_flow_ipv4_module_exit':
      nf_flow_table_ipv4.c:(.exit.text+0x8): undefined reference to `nft_unregister_flowtable_type'
      net/ipv4/netfilter/nf_flow_table_ipv4.o: In function `nf_flow_ipv4_module_init':
      nf_flow_table_ipv4.c:(.init.text+0x8): undefined reference to `nft_register_flowtable_type'
    
    This adds additional Kconfig dependencies to ensure that NF_CONNTRACK and NF_TABLES
    are always visible from NF_FLOW_TABLE, and that the internal dependencies between
    the four new modules are met.
    
    Fixes: 7c23b629 ("netfilter: flow table support for the mixed IPv4/IPv6 family")
    Fixes: 09952107 ("netfilter: flow table support for IPv6")
    Fixes: 97add9f0 ("netfilter: flow table support for IPv4")
    Signed-off-by: default avatarArnd Bergmann <arnd@arndb.de>
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    a0a97f2a
Kconfig 50.5 KB