netfilter: x_tables: allow to use default cgroup match
authorDaniel Borkmann <dborkman@redhat.com>
Mon, 18 Aug 2014 13:46:28 +0000 (15:46 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 5 Oct 2014 21:52:23 +0000 (14:52 -0700)
commitfcfebe9bc6c789eba97c06e125f23b3f9e261efa
tree8310ac19e56564d65de02acacbb0059b838abd17
parente19c985650c94578655f47cb6d856767c23b3433
netfilter: x_tables: allow to use default cgroup match

commit caa8ad94edf686d02b555c65a6162c0d1b434958 upstream.

There's actually no good reason why we cannot use cgroup id 0,
so lets just remove this artificial barrier.

Reported-by: Alexey Perevalov <a.perevalov@samsung.com>
Signed-off-by: Daniel Borkmann <dborkman@redhat.com>
Tested-by: Alexey Perevalov <a.perevalov@samsung.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/netfilter/xt_cgroup.c