+1
−0
+6
−8
+2
−3
+2
−0
+2
−0
Loading
Keep the conntrack reference until policy checks have been performed for IPsec V6 NAT support, just like ipv4. The reference needs to be dropped before a packet is queued to avoid having the conntrack module unloadable. Fixes: 58a317f1 ("netfilter: ipv6: add IPv6 NAT support") Signed-off-by:Madhu Koriginja <madhu.koriginja@nxp.com> Signed-off-by:
Florian Westphal <fw@strlen.de>