OSDN Git Service

netfilter: nft_last: honor NFTA_LAST_SET on restoration
authorPablo Neira Ayuso <pablo@netfilter.org>
Mon, 5 Jul 2021 15:45:36 +0000 (17:45 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 6 Jul 2021 12:15:13 +0000 (14:15 +0200)
NFTA_LAST_SET tells us if this expression has ever seen a packet, do not
ignore this attribute when restoring the ruleset.

Fixes: 836382dc2471 ("netfilter: nf_tables: add last expression")
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_last.c

index 913ac45..bbb352b 100644 (file)
@@ -23,15 +23,21 @@ static int nft_last_init(const struct nft_ctx *ctx, const struct nft_expr *expr,
 {
        struct nft_last_priv *priv = nft_expr_priv(expr);
        u64 last_jiffies;
+       u32 last_set = 0;
        int err;
 
-       if (tb[NFTA_LAST_MSECS]) {
+       if (tb[NFTA_LAST_SET]) {
+               last_set = ntohl(nla_get_be32(tb[NFTA_LAST_SET]));
+               if (last_set == 1)
+                       priv->last_set = 1;
+       }
+
+       if (last_set && tb[NFTA_LAST_MSECS]) {
                err = nf_msecs_to_jiffies64(tb[NFTA_LAST_MSECS], &last_jiffies);
                if (err < 0)
                        return err;
 
                priv->last_jiffies = jiffies + (unsigned long)last_jiffies;
-               priv->last_set = 1;
        }
 
        return 0;