summaryrefslogtreecommitdiffstats
path: root/package/firewall
diff options
context:
space:
mode:
authorjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>2010-09-28 11:38:31 +0000
committerjow <jow@3c298f89-4303-0410-b956-a3cf2f4a3e73>2010-09-28 11:38:31 +0000
commit43c3b75619cec98a71fd3bdc252990294853d4c1 (patch)
treec52c2261450f05f844fe045594c90b074fef22a2 /package/firewall
parent889cf1f8c372050c30dc35b269d04187e2a2c347 (diff)
[package] firewall: fix chain selection logic, option dest must be ignored for notrack targets
git-svn-id: svn://svn.openwrt.org/openwrt/trunk@23143 3c298f89-4303-0410-b956-a3cf2f4a3e73
Diffstat (limited to 'package/firewall')
-rw-r--r--package/firewall/files/lib/core_rule.sh11
1 files changed, 5 insertions, 6 deletions
diff --git a/package/firewall/files/lib/core_rule.sh b/package/firewall/files/lib/core_rule.sh
index dbaf1102e..a0de3ba8b 100644
--- a/package/firewall/files/lib/core_rule.sh
+++ b/package/firewall/files/lib/core_rule.sh
@@ -36,16 +36,15 @@ fw_load_rule() {
local table=f
local chain=input
- if [ "$rule_target" == "NOTRACK" ]; then
+ local target="${rule_target:-REJECT}"
+ if [ "$target" == "NOTRACK" ]; then
table=r
chain="zone_${rule_src}_notrack"
- elif [ -n "$rule_src" ]; then
- chain="zone_${rule_src}${rule_dest:+_forward}"
+ else
+ [ -n "$rule_src" ] && chain="zone_${rule_src}${rule_dest:+_forward}"
+ [ -n "$rule_dest" ] && target="zone_${rule_dest}_${target}"
fi
- local target="${rule_target:-REJECT}"
- [ -n "$dest" ] && target="zone_${rule_dest}_${target}"
-
local mode
fw_get_family_mode mode ${rule_family:-x} $rule_src I