about summary refs log tree commit diff
path: root/nixos
diff options
context:
space:
mode:
authorFranz Pletz <fpletz@fnordicwalking.de>2017-01-22 17:09:24 +0100
committerFranz Pletz <fpletz@fnordicwalking.de>2017-01-25 00:28:55 +0100
commit403fdd737eb353734591ee59711f8c5d26ca4f90 (patch)
treeebf11e10c97e26c1e122b75a1db478606659ba73 /nixos
parent4a914f2f9f9b2784d2bf78ee3cd56a7fd4e44e93 (diff)
downloadnixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar.gz
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar.bz2
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar.lz
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar.xz
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.tar.zst
nixlib-403fdd737eb353734591ee59711f8c5d26ca4f90.zip
linux: remove canDisableNetfilterConntrackHelpers feature
This feature is available in all kernels in nixpkgs.
Diffstat (limited to 'nixos')
-rw-r--r--nixos/modules/services/networking/firewall.nix3
1 files changed, 0 insertions, 3 deletions
diff --git a/nixos/modules/services/networking/firewall.nix b/nixos/modules/services/networking/firewall.nix
index c251b52e03fd..0b0ee57cf7ad 100644
--- a/nixos/modules/services/networking/firewall.nix
+++ b/nixos/modules/services/networking/firewall.nix
@@ -41,7 +41,6 @@ let
   kernelPackages = config.boot.kernelPackages;
 
   kernelHasRPFilter = kernelPackages.kernel.features.netfilterRPFilter or false;
-  kernelCanDisableHelpers = kernelPackages.kernel.features.canDisableNetfilterConntrackHelpers or false;
 
   helpers =
     ''
@@ -512,8 +511,6 @@ in
 
     assertions = [ { assertion = (cfg.checkReversePath != false) || kernelHasRPFilter;
                      message = "This kernel does not support rpfilter"; }
-                   { assertion = cfg.autoLoadConntrackHelpers || kernelCanDisableHelpers;
-                     message = "This kernel does not support disabling conntrack helpers"; }
                  ];
 
     systemd.services.firewall = {