netfilter: conntrack: limit sysctl setting for boolean options
authorTonghao Zhang <xiangxia.m.yue@gmail.com>
Sun, 7 Apr 2019 15:14:20 +0000 (08:14 -0700)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 30 Apr 2019 12:18:56 +0000 (14:18 +0200)
commit8f14c99c7edaaba9c0bb1727d44db6ebf157cc61
treec4af67ed0759fccd040c094f9219ef32ef094181
parenta4cb98f32c9046fea28bcb4979182f2ff731a27a
netfilter: conntrack: limit sysctl setting for boolean options

We use the zero and one to limit the boolean options setting.
After this patch we only set 0 or 1 to boolean options for nf
conntrack sysctl.

Signed-off-by: Tonghao Zhang <xiangxia.m.yue@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/net/netns/conntrack.h
net/netfilter/nf_conntrack_standalone.c