On Mon, Jan 28, 2019 at 4:00 PM Pablo Neira Ayuso <pa...@netfilter.org> wrote: > > From: Phil Sutter <p...@nwl.cc> > > To allow for a batch to contain rules in arbitrary ordering, introduce > NFTA_RULE_POSITION_ID attribute which works just like NFTA_RULE_POSITION > but contains the ID of another rule within the same batch. This helps > iptables-nft-restore handling dumps with mixed insert/append commands > correctly. > > Note that NFTA_RULE_POSITION takes precedence over > NFTA_RULE_POSITION_ID, so if the former is present, the latter is > ignored.
It looks like you forgot to add NFTA_RULE_POSITION_ID into nft_rule_policy[]?