netfilter: nft_limit: allow to invert matching criteria
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 28 Dec 2015 17:21:44 +0000 (18:21 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Sun, 3 Jan 2016 19:58:52 +0000 (20:58 +0100)
commitc7862a5f0de5f521c545f3436f0aa190964342dd
treef128e6751c4e20198b973dda2fd257d803bd02a5
parent5913beaf0d70f97135ed7191c028fd88b3848864
netfilter: nft_limit: allow to invert matching criteria

This patch allows you to invert the ratelimit matching criteria, so you
can match packets over the ratelimit. This is required to support what
hashlimit does.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/uapi/linux/netfilter/nf_tables.h
net/netfilter/nft_limit.c