summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPablo Neira Ayuso <pablo@netfilter.org>2019-08-16 11:23:58 +0200
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2019-09-21 07:16:54 +0200
commita02c676c0f03ee56f3fca6c30fa54c365e2278d7 (patch)
treed663349f50a489fc5c716894532283bf9c26bbca
parenta4fa6c68ecc3b92f938b6460ef298bc5dd4cec27 (diff)
downloadlinux-stable-a02c676c0f03ee56f3fca6c30fa54c365e2278d7.tar.gz
linux-stable-a02c676c0f03ee56f3fca6c30fa54c365e2278d7.tar.bz2
linux-stable-a02c676c0f03ee56f3fca6c30fa54c365e2278d7.zip
netfilter: nft_flow_offload: missing netlink attribute policy
[ Upstream commit 14c415862c0630e01712a4eeaf6159a2b1b6d2a4 ] The netlink attribute policy for NFTA_FLOW_TABLE_NAME is missing. Fixes: a3c90f7a2323 ("netfilter: nf_tables: flow offload expression") Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
-rw-r--r--net/netfilter/nft_flow_offload.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/net/netfilter/nft_flow_offload.c b/net/netfilter/nft_flow_offload.c
index 69decbe2c988..1ef8cb789c41 100644
--- a/net/netfilter/nft_flow_offload.c
+++ b/net/netfilter/nft_flow_offload.c
@@ -149,6 +149,11 @@ static int nft_flow_offload_validate(const struct nft_ctx *ctx,
return nft_chain_validate_hooks(ctx->chain, hook_mask);
}
+static const struct nla_policy nft_flow_offload_policy[NFTA_FLOW_MAX + 1] = {
+ [NFTA_FLOW_TABLE_NAME] = { .type = NLA_STRING,
+ .len = NFT_NAME_MAXLEN - 1 },
+};
+
static int nft_flow_offload_init(const struct nft_ctx *ctx,
const struct nft_expr *expr,
const struct nlattr * const tb[])
@@ -207,6 +212,7 @@ static const struct nft_expr_ops nft_flow_offload_ops = {
static struct nft_expr_type nft_flow_offload_type __read_mostly = {
.name = "flow_offload",
.ops = &nft_flow_offload_ops,
+ .policy = nft_flow_offload_policy,
.maxattr = NFTA_FLOW_MAX,
.owner = THIS_MODULE,
};