aboutsummaryrefslogtreecommitdiff
path: root/net/netfilter/nft_masq.c
diff options
context:
space:
mode:
authorGravatar Florian Westphal <fw@strlen.de> 2023-07-18 09:52:30 +0200
committerGravatar Florian Westphal <fw@strlen.de> 2023-07-27 13:45:51 +0200
commit100a11b69842ab568cff2a59959daf317be525c9 (patch)
tree6ec67965f4fd5c9b607839e58acb5b7daf2c0671 /net/netfilter/nft_masq.c
parentnetlink: allow be16 and be32 types in all uint policy checks (diff)
downloadlinux-100a11b69842ab568cff2a59959daf317be525c9.tar.gz
linux-100a11b69842ab568cff2a59959daf317be525c9.tar.bz2
linux-100a11b69842ab568cff2a59959daf317be525c9.zip
netfilter: nf_tables: use NLA_POLICY_MASK to test for valid flag options
nf_tables relies on manual test of netlink attributes coming from userspace even in cases where this could be handled via netlink policy. Convert a bunch of 'flag' attributes to use NLA_POLICY_MASK checks. Signed-off-by: Florian Westphal <fw@strlen.de>
Diffstat (limited to 'net/netfilter/nft_masq.c')
-rw-r--r--net/netfilter/nft_masq.c8
1 files changed, 3 insertions, 5 deletions
diff --git a/net/netfilter/nft_masq.c b/net/netfilter/nft_masq.c
index b115d77fbbc7..8a14aaca93bb 100644
--- a/net/netfilter/nft_masq.c
+++ b/net/netfilter/nft_masq.c
@@ -20,7 +20,8 @@ struct nft_masq {
};
static const struct nla_policy nft_masq_policy[NFTA_MASQ_MAX + 1] = {
- [NFTA_MASQ_FLAGS] = { .type = NLA_U32 },
+ [NFTA_MASQ_FLAGS] =
+ NLA_POLICY_MASK(NLA_BE32, NF_NAT_RANGE_MASK),
[NFTA_MASQ_REG_PROTO_MIN] = { .type = NLA_U32 },
[NFTA_MASQ_REG_PROTO_MAX] = { .type = NLA_U32 },
};
@@ -47,11 +48,8 @@ static int nft_masq_init(const struct nft_ctx *ctx,
struct nft_masq *priv = nft_expr_priv(expr);
int err;
- if (tb[NFTA_MASQ_FLAGS]) {
+ if (tb[NFTA_MASQ_FLAGS])
priv->flags = ntohl(nla_get_be32(tb[NFTA_MASQ_FLAGS]));
- if (priv->flags & ~NF_NAT_RANGE_MASK)
- return -EINVAL;
- }
if (tb[NFTA_MASQ_REG_PROTO_MIN]) {
err = nft_parse_register_load(tb[NFTA_MASQ_REG_PROTO_MIN],