summary | shortlog | log | commit | commitdiff | tree
raw | patch | inline | side by side (parent: b89c87d)
raw | patch | inline | side by side (parent: b89c87d)
author | Pablo Neira Ayuso <pablo@netfilter.org> | |
Tue, 17 Mar 2015 12:21:42 +0000 (13:21 +0100) | ||
committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | |
Sat, 4 Jul 2015 02:49:05 +0000 (19:49 -0700) |
commit d6b6cb1d3e6f78d55c2d4043d77d0d8def3f3b99 upstream.
If there's an existing base chain, we have to allow to change the
default policy without indicating the hook information.
However, if the chain doesn't exists, we have to enforce the presence of
the hook attribute.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
If there's an existing base chain, we have to allow to change the
default policy without indicating the hook information.
However, if the chain doesn't exists, we have to enforce the presence of
the hook attribute.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
net/netfilter/nf_tables_api.c | patch | blob | history |
index c68e5e0628df86e9aae4db0dea2af5551adbfc3f..99de2409f7314cd4f46b95812ce4694a77a8cabd 100644 (file)
if (nla[NFTA_CHAIN_POLICY]) {
if ((chain != NULL &&
- !(chain->flags & NFT_BASE_CHAIN)) ||
+ !(chain->flags & NFT_BASE_CHAIN)))
+ return -EOPNOTSUPP;
+
+ if (chain == NULL &&
nla[NFTA_CHAIN_HOOK] == NULL)
return -EOPNOTSUPP;