The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH] bpf: fix netfilter link comparison to handle unsigned flags
@ 2025-09-19  9:04 Haofeng Li
  2025-09-20  0:22 ` Quentin Monnet
  0 siblings, 1 reply; 4+ messages in thread
From: Haofeng Li @ 2025-09-19  9:04 UTC (permalink / raw)
  To: Quentin Monnet, Alexei Starovoitov
  Cc: Daniel Borkmann, Andrii Nakryiko, linux-kernel, Haofeng Li,
	lihaofeng

From: lihaofeng <lihaofeng@kylinos.cn>

The original implementation of netfilter_link_compar() used subtraction
to compare the netfilter.flags field, which is  an unsigned type.
This could result in incorrect comparison results when the unsigned
value wrapped around due to underflow.

Changed the comparison logic for flags to use explicit conditional
checks (similar to how priority is handled) instead of subtraction,
ensuring correct negative/zero/positive return values regardless of
the underlying data type.

This fixes potential sorting issues when using this comparison function
with algorithms like qsort() or bsearch().

Signed-off-by: lihaofeng <lihaofeng@kylinos.cn>
---
 tools/bpf/bpftool/net.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/tools/bpf/bpftool/net.c b/tools/bpf/bpftool/net.c
index cfc6f944f7c3..9f840821beda 100644
--- a/tools/bpf/bpftool/net.c
+++ b/tools/bpf/bpftool/net.c
@@ -816,7 +816,11 @@ static int netfilter_link_compar(const void *a, const void *b)
 	if (nfa->netfilter.priority > nfb->netfilter.priority)
 		return 1;
 
-	return nfa->netfilter.flags - nfb->netfilter.flags;
+	if (nfa->netfilter.flags < nfb->netfilter.flags)
+		return -1;
+	if (nfa->netfilter.flags > nfb->netfilter.flags)
+		return 1;
+	return 0;
 }
 
 static void show_link_netfilter(void)
-- 
2.25.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2025-09-22  2:20 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-09-19  9:04 [PATCH] bpf: fix netfilter link comparison to handle unsigned flags Haofeng Li
2025-09-20  0:22 ` Quentin Monnet
2025-09-22  1:45   ` Haofeng Li
2025-09-22  2:20     ` Alexei Starovoitov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox