From: Florian Westphal <fw@strlen.de>
To: Phil Sutter <phil@nwl.cc>
Cc: Pablo Neira Ayuso <pablo@netfilter.org>,
netfilter-devel@vger.kernel.org, Florian Westphal <fw@strlen.de>,
Eric Garver <e@erig.me>
Subject: Re: [nf-next PATCH v3 03/16] netfilter: nf_tables: Store user-defined hook ifname
Date: Thu, 12 Sep 2024 14:56:41 +0200 [thread overview]
Message-ID: <20240912125641.GA2892@breakpoint.cc> (raw)
In-Reply-To: <20240912122148.12159-4-phil@nwl.cc>
Phil Sutter <phil@nwl.cc> wrote:
> Prepare for hooks with NULL ops.dev pointer (due to non-existent device)
> and store the interface name and length as specified by the user upon
> creation. No functional change intended.
>
> Signed-off-by: Phil Sutter <phil@nwl.cc>
> ---
> include/net/netfilter/nf_tables.h | 2 ++
> net/netfilter/nf_tables_api.c | 6 +++---
> 2 files changed, 5 insertions(+), 3 deletions(-)
>
> diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h
> index c302b396e1a7..efd6b55b4914 100644
> --- a/include/net/netfilter/nf_tables.h
> +++ b/include/net/netfilter/nf_tables.h
> @@ -1191,6 +1191,8 @@ struct nft_hook {
> struct list_head list;
> struct nf_hook_ops ops;
> struct rcu_head rcu;
> + char ifname[IFNAMSIZ];
> + u8 ifnamelen;
> };
>
> /**
> diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
> index 3ffb728309af..f1710aab5188 100644
> --- a/net/netfilter/nf_tables_api.c
> +++ b/net/netfilter/nf_tables_api.c
> @@ -2173,7 +2173,6 @@ static struct nft_hook *nft_netdev_hook_alloc(struct net *net,
> const struct nlattr *attr)
> {
> struct net_device *dev;
> - char ifname[IFNAMSIZ];
> struct nft_hook *hook;
> int err;
>
> @@ -2183,12 +2182,13 @@ static struct nft_hook *nft_netdev_hook_alloc(struct net *net,
> goto err_hook_alloc;
> }
>
> - nla_strscpy(ifname, attr, IFNAMSIZ);
> + nla_strscpy(hook->ifname, attr, IFNAMSIZ);
> + hook->ifnamelen = nla_len(attr);
Hmm. nft_netdev_hook_alloc has no netlink attribute policy validation
:-/
Can you add another patch that fixes this up?
I'd suggest to move the if (nla_type(tmp) != NFTA_DEVICE_NAME)
test from nf_tables_parse_netdev_hooks() into nft_netdev_hook_alloc
so nft_chain_parse_netdev() also has this test.
Then,
> - nla_strscpy(ifname, attr, IFNAMSIZ);
Into:
err = nla_strscpy(ifname, attr, IFNAMSIZ)
if (err < 0)
goto err_hook_dev;
so we validate that
a) attr is NFTA_DEVICE_NAME
b) length doesn't exceed IFNAMSIZ.
ATM this check is implicit because nla_strscpy() always
null-terminates and the next line will check that the
device with this name actually exists.
But that check is removed later.
This patch can then set
hook->ifnamelen = err
without risk that nla_len() returns 0xfff0 or some other bogus
value.
next prev parent reply other threads:[~2024-09-12 12:56 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-12 12:21 [nf-next PATCH v3 00/16] Dynamic hook interface binding Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 01/16] netfilter: nf_tables: Keep deleted flowtable hooks until after RCU Phil Sutter
2024-09-12 13:32 ` Florian Westphal
2024-09-12 13:48 ` Phil Sutter
2024-09-12 14:27 ` Florian Westphal
2024-09-16 0:00 ` Pablo Neira Ayuso
2024-09-16 21:42 ` Pablo Neira Ayuso
2024-09-17 21:14 ` Pablo Neira Ayuso
2024-09-12 12:21 ` [nf-next PATCH v3 02/16] netfilter: nf_tables: Flowtable hook's pf value never varies Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 03/16] netfilter: nf_tables: Store user-defined hook ifname Phil Sutter
2024-09-12 12:56 ` Florian Westphal [this message]
2024-09-12 13:26 ` Phil Sutter
2024-09-12 13:38 ` Florian Westphal
2024-09-12 12:21 ` [nf-next PATCH v3 04/16] netfilter: nf_tables: Use stored ifname in netdev hook dumps Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 05/16] netfilter: nf_tables: Compare netdev hooks based on stored name Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 06/16] netfilter: nf_tables: Tolerate chains with no remaining hooks Phil Sutter
2024-10-31 14:01 ` Florian Westphal
2024-10-31 14:19 ` Phil Sutter
2024-10-31 14:37 ` Florian Westphal
2024-10-31 15:16 ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 07/16] netfilter: nf_tables: Introduce functions freeing nft_hook objects Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 08/16] netfilter: nf_tables: Introduce nft_hook_find_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 09/16] netfilter: nf_tables: Introduce nft_register_flowtable_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 10/16] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 11/16] netfilter: nf_tables: chain: Respect NETDEV_REGISTER events Phil Sutter
2024-09-12 14:40 ` Florian Westphal
2024-09-12 15:05 ` Phil Sutter
2024-09-12 15:12 ` Florian Westphal
2024-09-12 15:41 ` Phil Sutter
2024-09-12 16:06 ` Florian Westphal
2024-09-12 16:25 ` Phil Sutter
2024-09-12 20:43 ` Florian Westphal
2024-09-13 11:42 ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 12/16] netfilter: nf_tables: flowtable: " Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 13/16] netfilter: nf_tables: Handle NETDEV_CHANGENAME events Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 14/16] netfilter: nf_tables: Support wildcard netdev hook specs Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 15/16] netfilter: nf_tables: Add notications for hook changes Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 16/16] selftests: netfilter: Torture nftables netdev hooks Phil Sutter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240912125641.GA2892@breakpoint.cc \
--to=fw@strlen.de \
--cc=e@erig.me \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.