59 lines
2.1 KiB
Diff
59 lines
2.1 KiB
Diff
From ee1d70170aaa417e064d9f98e029e5aef0dd4397 Mon Sep 17 00:00:00 2001
|
|
From: Florian Westphal <fwestpha@redhat.com>
|
|
Date: Wed, 13 May 2026 17:15:53 +0200
|
|
Subject: [PATCH] netfilter: nf_tables: always walk all pending catchall
|
|
elements
|
|
|
|
JIRA: https://redhat.atlassian.net/browse/RHEL-168848
|
|
Upstream Status: commit 7cb9a23d7ae4
|
|
|
|
commit 7cb9a23d7ae40a702577d3d8bacb7026f04ac2a9
|
|
Author: Florian Westphal <fw@strlen.de>
|
|
Date: Thu Mar 5 21:32:00 2026 +0100
|
|
|
|
netfilter: nf_tables: always walk all pending catchall elements
|
|
|
|
During transaction processing we might have more than one catchall element:
|
|
1 live catchall element and 1 pending element that is coming as part of the
|
|
new batch.
|
|
|
|
If the map holding the catchall elements is also going away, its
|
|
required to toggle all catchall elements and not just the first viable
|
|
candidate.
|
|
|
|
Otherwise, we get:
|
|
WARNING: ./include/net/netfilter/nf_tables.h:1281 at nft_data_release+0xb7/0xe0 [nf_tables], CPU#2: nft/1404
|
|
RIP: 0010:nft_data_release+0xb7/0xe0 [nf_tables]
|
|
[..]
|
|
__nft_set_elem_destroy+0x106/0x380 [nf_tables]
|
|
nf_tables_abort_release+0x348/0x8d0 [nf_tables]
|
|
nf_tables_abort+0xcf2/0x3ac0 [nf_tables]
|
|
nfnetlink_rcv_batch+0x9c9/0x20e0 [..]
|
|
|
|
Fixes: 628bd3e49cba ("netfilter: nf_tables: drop map element references from preparation phase")
|
|
Reported-by: Yiming Qian <yimingqian591@gmail.com>
|
|
Signed-off-by: Florian Westphal <fw@strlen.de>
|
|
|
|
Signed-off-by: Florian Westphal <fwestpha@redhat.com>
|
|
|
|
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
|
|
index 5d244d3..55434ea 100644
|
|
--- a/net/netfilter/nf_tables_api.c
|
|
+++ b/net/netfilter/nf_tables_api.c
|
|
@@ -828,7 +828,6 @@ static void nft_map_catchall_deactivate(const struct nft_ctx *ctx,
|
|
|
|
nft_set_elem_change_active(ctx->net, set, ext);
|
|
nft_setelem_data_deactivate(ctx->net, set, catchall->elem);
|
|
- break;
|
|
}
|
|
}
|
|
|
|
@@ -5918,7 +5917,6 @@ static void nft_map_catchall_activate(const struct nft_ctx *ctx,
|
|
|
|
nft_clear(ctx->net, ext);
|
|
nft_setelem_data_activate(ctx->net, set, catchall->elem);
|
|
- break;
|
|
}
|
|
}
|
|
|