]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_tables: split chain policy validation from actually setting it
authorPatrick McHardy <kaber@trash.net>
Thu, 9 Jan 2014 18:42:31 +0000 (18:42 +0000)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 9 Jan 2014 19:17:13 +0000 (20:17 +0100)
commit18a1cfa98f6f20b62f97a3875f4bc3a4b6c94e4d
treecb7657b0a5752388c10f320db7e2d7db9767cb69
parent3f1b23b9fa4bb2141cc48bd7b220a6bcff0acc7e
netfilter: nf_tables: split chain policy validation from actually setting it

Currently nf_tables_newchain() atomicity is broken because of having
validation of some netlink attributes performed after changing attributes
of the chain. The chain policy is (currently) fine, but split it up as
preparation for the following fixes and to avoid future mistakes.

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c