From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Subject: [PATCH nft 1/3] segtree: assert on value expressions
Date: Mon, 24 Aug 2026 23:29:07 +0200 [thread overview]
Message-ID: <20260824212909.68597-1-pablo@netfilter.org> (raw)
Assert value expression before performing math on them instead of
crashing with unsupported expressions.
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
---
src/segtree.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/src/segtree.c b/src/segtree.c
index c8a7a3541ac3..4f758e6c9f99 100644
--- a/src/segtree.c
+++ b/src/segtree.c
@@ -253,6 +253,9 @@ int get_set_decompose(struct set *cache_set, struct set *set)
if (i->key->flags & EXPR_F_INTERVAL_END && left) {
list_del(&left->list);
list_del(&i->list);
+
+ assert(i->key->etype == EXPR_VALUE);
+
mpz_sub_ui(i->key->value, i->key->value, 1);
range = get_set_interval_find(cache_set, left, i);
if (!range) {
@@ -325,6 +328,10 @@ static int expr_value_cmp(const void *p1, const void *p2)
return -1;
key_e2 = expr_value(e2);
+
+ assert(key_e1->etype == EXPR_VALUE);
+ assert(key_e2->etype == EXPR_VALUE);
+
ret = mpz_cmp(key_e1->value, key_e2->value);
if (ret == 0) {
if (e1->key->flags & EXPR_F_INTERVAL_END)
@@ -592,6 +599,10 @@ add_interval(struct expr *set, struct expr *low, struct expr *i, bool closed)
mpz_init(p);
key = expr_value(low);
+
+ assert(expr_value(i)->etype == EXPR_VALUE);
+ assert(key->etype == EXPR_VALUE);
+
mpz_sub(range, expr_value(i)->value, key->value);
if (closed)
mpz_sub_ui(range, range, 1);
--
2.47.3
next reply other threads:[~2026-08-24 21:29 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 21:29 Pablo Neira Ayuso [this message]
2026-08-24 21:29 ` [PATCH nft 2/3] Revert "segtree: basic support for binary operations in concatenated set ranges" Pablo Neira Ayuso
2026-08-24 21:29 ` [PATCH nft 3/3] segtree: postpone bitmask to symbol conversion for interval sets Pablo Neira Ayuso
2026-08-27 9:03 ` [PATCH nft 1/3] segtree: assert on value expressions Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824212909.68597-1-pablo@netfilter.org \
--to=pablo@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.