netfilter: nf_tables: move hardware offload step after building the chain blob

Allocate the chain blob before the ruleset offload to reduce chances of
entering an inconsistent state where the offloaded ruleset in the nic
and the software ruleset differ.

Fixes: c9626a2cbd ("netfilter: nf_tables: add hardware offload support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
Pablo Neira Ayuso
2026-08-13 02:16:02 +02:00
parent 9b4ab1f3fe
commit b1881d362e

View File

@@ -10982,10 +10982,6 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
return -EAGAIN;
}
err = nft_flow_rule_offload_commit(net);
if (err < 0)
return err;
/* 1. Allocate space for next generation rules_gen_X[] */
list_for_each_entry_safe(trans, next, &nft_net->commit_list, list) {
struct nft_table *table = trans->table;
@@ -11010,6 +11006,16 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
}
}
/* must be last, so audit and chain blob set up does not leave hardware
* in consistent state.
*/
err = nft_flow_rule_offload_commit(net);
if (err < 0) {
nf_tables_commit_chain_prepare_cancel(net);
nf_tables_commit_audit_free(&adl);
return err;
}
/* step 2. Make rules_gen_X visible to packet path */
nft_set_commit_update(&ctx, nft_net);