From: Pavel Tikhomirov <ptikhomi...@virtuozzo.com> Need it for docker Docker nat rules c/r in nft based environment.
https://jira.sw.ru/browse/PSBM-125002 Signed-off-by: Pavel Tikhomirov <ptikhomi...@virtuozzo.com> ++++ ve/kmod: fix misprint in fib modules autoload allow rules When testing criu to suspend resume "fib" rules I found out that we have wrong names for fib module aliases, and thus can't load them on restore if they are not yet loaded. Perf shows when restoring centos 8 CT with docker: probe:module_payload_iptable_allowed: module_string="nft-expr-2-fib" https://jira.sw.ru/browse/PSBM-125002 mFixes: 84beb0e73874a ("ve/kmod: make fib modules autoloadable from CT") Signed-off-by: Pavel Tikhomirov <ptikhomi...@virtuozzo.com> (cherry picked from vz7 commit ("f4eb6e8a5a78 ve/kmod: make fib modules autoloadable from CT") Signed-off-by: Konstantin Khorenko <khore...@virtuozzo.com> --- kernel/kmod.c | 1 + 1 file changed, 1 insertion(+) diff --git a/kernel/kmod.c b/kernel/kmod.c index 1ff56543f59d..678735dbb969 100644 --- a/kernel/kmod.c +++ b/kernel/kmod.c @@ -232,6 +232,7 @@ static const char * const ve0_allowed_mod[] = { "nf_synproxy_core", "nft-set", + "nft_fib", "nf_tproxy_ipv4", "nf_tproxy_ipv6", _______________________________________________ Devel mailing list Devel@openvz.org https://lists.openvz.org/mailman/listinfo/devel