summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorTamaki Yanagawa <ty@000ty.net>2026-07-03 16:22:57 +0000
committerFlorian Westphal <fw@strlen.de>2026-07-08 15:33:37 +0200
commite6107a4c74b54cb33e3bce162a63048ae5a6b198 (patch)
tree7eb26e84bfb0137112bcfc8fc943d82d1246c37d
parent084d23f818321390509e9738a0b08bbf46df6425 (diff)
downloadlinux-next-e6107a4c74b54cb33e3bce162a63048ae5a6b198.tar.gz
linux-next-e6107a4c74b54cb33e3bce162a63048ae5a6b198.zip
netfilter: nft_lookup: fix catchall element handling with inverted lookups
nft_lookup_eval() decides whether a lookup matched (`found`) from the direct set lookup and priv->invert before falling back to the catchall element used by interval sets (e.g. nft_set_rbtree) for the open-ended default range. Since `found` is never recomputed after `ext` is replaced by the catchall lookup, inverted lookups (NFT_LOOKUP_F_INV, "!= @set") can wrongly match or wrongly skip the catchall element, producing the wrong verdict. Fold the catchall lookup into `ext` before computing `found`, matching the order already used by nft_objref_map_eval(). Fixes: aaa31047a6d2 ("netfilter: nftables: add catch-all set element support") Signed-off-by: Tamaki Yanagawa <ty@000ty.net> Assisted-by: Claude:claude-sonnet-5 Signed-off-by: Florian Westphal <fw@strlen.de>
-rw-r--r--net/netfilter/nft_lookup.c10
1 files changed, 5 insertions, 5 deletions
diff --git a/net/netfilter/nft_lookup.c b/net/netfilter/nft_lookup.c
index ba512e94b402..19887439847d 100644
--- a/net/netfilter/nft_lookup.c
+++ b/net/netfilter/nft_lookup.c
@@ -103,13 +103,13 @@ void nft_lookup_eval(const struct nft_expr *expr,
bool found;
ext = nft_set_do_lookup(net, set, &regs->data[priv->sreg]);
+ if (!ext)
+ ext = nft_set_catchall_lookup(net, set);
+
found = !!ext ^ priv->invert;
if (!found) {
- ext = nft_set_catchall_lookup(net, set);
- if (!ext) {
- regs->verdict.code = NFT_BREAK;
- return;
- }
+ regs->verdict.code = NFT_BREAK;
+ return;
}
if (ext) {