* [nft PATCH v2] Reject invalid chain priority values in user space
@ 2023-03-10 11:23 Phil Sutter
2023-03-10 11:44 ` Pablo Neira Ayuso
2023-03-10 11:46 ` Phil Sutter
0 siblings, 2 replies; 3+ messages in thread
From: Phil Sutter @ 2023-03-10 11:23 UTC (permalink / raw)
To: Pablo Neira Ayuso; +Cc: netfilter-devel
The kernel doesn't accept nat type chains with a priority of -200 or
below. Catch this and provide a better error message than the kernel's
EOPNOTSUPP.
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
Changes since v1:
- Pull mpz_export_data() call out of the conditional.
- Check priority value before calling strcmp(), it's less expensive.
- Reword the error message as suggested.
---
src/evaluate.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/src/evaluate.c b/src/evaluate.c
index d24f8b66b0de8..21831201519dd 100644
--- a/src/evaluate.c
+++ b/src/evaluate.c
@@ -4842,6 +4842,8 @@ static int chain_evaluate(struct eval_ctx *ctx, struct chain *chain)
}
if (chain->flags & CHAIN_F_BASECHAIN) {
+ int priority;
+
chain->hook.num = str2hooknum(chain->handle.family,
chain->hook.name);
if (chain->hook.num == NF_INET_NUMHOOKS)
@@ -4854,6 +4856,13 @@ static int chain_evaluate(struct eval_ctx *ctx, struct chain *chain)
return __stmt_binary_error(ctx, &chain->priority.loc, NULL,
"invalid priority expression %s in this context.",
expr_name(chain->priority.expr));
+
+ mpz_export_data(&priority, chain->priority.expr->value,
+ BYTEORDER_HOST_ENDIAN, sizeof(int));
+ if (priority <= -200 && !strcmp(chain->type.str, "nat"))
+ return __stmt_binary_error(ctx, &chain->priority.loc, NULL,
+ "Chains of type \"nat\" must have a priority value above -200.");
+
if (chain->policy) {
expr_set_context(&ctx->ectx, &policy_type,
NFT_NAME_MAXLEN * BITS_PER_BYTE);
--
2.38.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [nft PATCH v2] Reject invalid chain priority values in user space
2023-03-10 11:23 [nft PATCH v2] Reject invalid chain priority values in user space Phil Sutter
@ 2023-03-10 11:44 ` Pablo Neira Ayuso
2023-03-10 11:46 ` Phil Sutter
1 sibling, 0 replies; 3+ messages in thread
From: Pablo Neira Ayuso @ 2023-03-10 11:44 UTC (permalink / raw)
To: Phil Sutter; +Cc: netfilter-devel
On Fri, Mar 10, 2023 at 12:23:48PM +0100, Phil Sutter wrote:
> The kernel doesn't accept nat type chains with a priority of -200 or
> below. Catch this and provide a better error message than the kernel's
> EOPNOTSUPP.
LGTM
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [nft PATCH v2] Reject invalid chain priority values in user space
2023-03-10 11:23 [nft PATCH v2] Reject invalid chain priority values in user space Phil Sutter
2023-03-10 11:44 ` Pablo Neira Ayuso
@ 2023-03-10 11:46 ` Phil Sutter
1 sibling, 0 replies; 3+ messages in thread
From: Phil Sutter @ 2023-03-10 11:46 UTC (permalink / raw)
To: Pablo Neira Ayuso; +Cc: netfilter-devel
On Fri, Mar 10, 2023 at 12:23:48PM +0100, Phil Sutter wrote:
> The kernel doesn't accept nat type chains with a priority of -200 or
> below. Catch this and provide a better error message than the kernel's
> EOPNOTSUPP.
>
> Signed-off-by: Phil Sutter <phil@nwl.cc>
Patch applied.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2023-03-10 11:46 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-03-10 11:23 [nft PATCH v2] Reject invalid chain priority values in user space Phil Sutter
2023-03-10 11:44 ` Pablo Neira Ayuso
2023-03-10 11:46 ` Phil Sutter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox