]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nftables: relax check for stateful expressions in set definition
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 8 Feb 2021 12:20:47 +0000 (13:20 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Mon, 8 Feb 2021 23:50:14 +0000 (00:50 +0100)
commitf6dbcdd08ca6b9bf063ff97fb8153d1e5d227ab6
tree2f9749a0bb017e4ef4358bc18e6f2708bd616280
parent720e66ff1c10539487e2a82666f72c4888090d05
netfilter: nftables: relax check for stateful expressions in set definition

Restore the original behaviour where users are allowed to add an element
with any stateful expression if the set definition specifies no stateful
expressions. Make sure upper maximum number of stateful expressions of
NFT_SET_EXPR_MAX is not reached.

Fixes: 5652d97caa02 ("netfilter: nftables: generalize set expressions support")
Fixes: 145851b93448 ("netfilter: nftables: netlink support for several set element expressions")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c