Re: xt_recent broken in kernel 3.19.0 + PATCH

From: Chris Vine
Date: Thu Feb 12 2015 - 06:16:46 EST

On Thu, 12 Feb 2015 10:54:17 +0000
Chris Vine <chris@xxxxxxxxxxxxxxxxxxxxx> wrote:
> On further testing I see that that patch only solves the problem if
> SSH_TRIES is set to a power of two boundary. You still get an error
> loading the rule if it is anything else. I think there is something
> wrong with the nstamp_mask heuristic which is used here.

I now find that that is not right either. I had to rmmod xt_recent to
get it to drop its previous setting. With that done, the patch does
indeed seem to work for all values of SSH_TRIES.

