Commit cc003c7e authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso

netfilter: nft_payload: cancel register tracking after payload update

The payload expression might mangle the packet, cancel register tracking
since any payload data in the registers is stale.

Finer grain register tracking cancellation by inspecting the payload
base, offset and length on the register is also possible.
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent be5650f8
...@@ -798,12 +798,33 @@ static int nft_payload_set_dump(struct sk_buff *skb, const struct nft_expr *expr ...@@ -798,12 +798,33 @@ static int nft_payload_set_dump(struct sk_buff *skb, const struct nft_expr *expr
return -1; return -1;
} }
static bool nft_payload_set_reduce(struct nft_regs_track *track,
const struct nft_expr *expr)
{
int i;
for (i = 0; i < NFT_REG32_NUM; i++) {
if (!track->regs[i].selector)
continue;
if (track->regs[i].selector->ops != &nft_payload_ops &&
track->regs[i].selector->ops != &nft_payload_fast_ops)
continue;
track->regs[i].selector = NULL;
track->regs[i].bitwise = NULL;
}
return false;
}
static const struct nft_expr_ops nft_payload_set_ops = { static const struct nft_expr_ops nft_payload_set_ops = {
.type = &nft_payload_type, .type = &nft_payload_type,
.size = NFT_EXPR_SIZE(sizeof(struct nft_payload_set)), .size = NFT_EXPR_SIZE(sizeof(struct nft_payload_set)),
.eval = nft_payload_set_eval, .eval = nft_payload_set_eval,
.init = nft_payload_set_init, .init = nft_payload_set_init,
.dump = nft_payload_set_dump, .dump = nft_payload_set_dump,
.reduce = nft_payload_set_reduce,
}; };
static const struct nft_expr_ops * static const struct nft_expr_ops *
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment