mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-31 09:20:13 -04:00
netfilter: nf_tables: move hardware offload step after building the chain blob
Allocate the chain blob before the ruleset offload to reduce chances of
entering an inconsistent state where the offloaded ruleset in the nic
and the software ruleset differ.
Fixes: c9626a2cbd ("netfilter: nf_tables: add hardware offload support")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
This commit is contained in:
@@ -10982,10 +10982,6 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
|
||||
return -EAGAIN;
|
||||
}
|
||||
|
||||
err = nft_flow_rule_offload_commit(net);
|
||||
if (err < 0)
|
||||
return err;
|
||||
|
||||
/* 1. Allocate space for next generation rules_gen_X[] */
|
||||
list_for_each_entry_safe(trans, next, &nft_net->commit_list, list) {
|
||||
struct nft_table *table = trans->table;
|
||||
@@ -11010,6 +11006,16 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
|
||||
}
|
||||
}
|
||||
|
||||
/* must be last, so audit and chain blob set up does not leave hardware
|
||||
* in consistent state.
|
||||
*/
|
||||
err = nft_flow_rule_offload_commit(net);
|
||||
if (err < 0) {
|
||||
nf_tables_commit_chain_prepare_cancel(net);
|
||||
nf_tables_commit_audit_free(&adl);
|
||||
return err;
|
||||
}
|
||||
|
||||
/* step 2. Make rules_gen_X visible to packet path */
|
||||
nft_set_commit_update(&ctx, nft_net);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user