]> git.dujemihanovic.xyz Git - linux.git/commitdiff
netfilter: nf_tables: use rcu chain hook list iterator from netlink dump path
authorPablo Neira Ayuso <pablo@netfilter.org>
Tue, 17 Sep 2024 21:07:46 +0000 (23:07 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Thu, 26 Sep 2024 11:03:02 +0000 (13:03 +0200)
Lockless iteration over hook list is possible from netlink dump path,
use rcu variant to iterate over the hook list as is done with flowtable
hooks.

Fixes: b9703ed44ffb ("netfilter: nf_tables: support for adding new devices to an existing netdev chain")
Reported-by: Phil Sutter <phil@nwl.cc>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_tables_api.c

index 042080aeb46c105b655266e87a9e34a7edb485cf..8f073e6c772a5f134c8d1c35c3d0edc69b43be23 100644 (file)
@@ -1849,7 +1849,7 @@ static int nft_dump_basechain_hook(struct sk_buff *skb, int family,
                if (!hook_list)
                        hook_list = &basechain->hook_list;
 
-               list_for_each_entry(hook, hook_list, list) {
+               list_for_each_entry_rcu(hook, hook_list, list) {
                        if (!first)
                                first = hook;